beclassified and approved for-release by NSA on 09-19-2005 pursuant to E.O. 12958, 

as amended 


Bestristc d - 

WAR DEPARTMENT 

OFFICE OF THE CHIEF SIGNAL OFFICER 
WASHINGTON 

MILITARY CRYPTANALYSIS 
Part I 

MONOALPHABETIC SUBSTITUTION SYSTEMS 

By 

WILLIAM F. FRIEDMAN 

Principal Cryptanalyst 
Chief of Signal Intelligence Section 
War Plans and Training Division 


PBEPAKEO UNDEB THE DIRECTION OP THE 
CHIEF SIGNAt, OFFICES 


tTNlTED STATES 

GOVERNMENT PRINTING OFFICE 
WASHINGTON 11918 






MILITARY CRYPTANALYSIS, PART I. MONOALPHABETIC SUBSTITUTION 
SYSTEMS 

Section Paragraphs Pages 

I. Introductory remarks_ 1-3 1-6 

II. Fundament^ principles__-. 4- 8 7-10 

III. Frequency distributions. 0-11 11-17 

IV. Fundamental uses of the uniliteral frequency distribution-. 12-16 18-26 

V. Uniliteral substitution with standard cipher alphabets. 17-22 27-39 

VI. Uniliteral substitution with mixed cipher alphabets. 23-34 40-58 

VII. Multiliteral substitution with single-equivalent cipher alphabets.. 35-36 59-62 

VIII. Multiliteral substitution with multiple-equivalent cipher alphabets—. 37-40 63-69 

Polygraphio substitution systems._ 41-46 70-98 

Concluding remarks_ 47-50 99-104 


cm) 












Section I 

INTRODUCTORY REMARKS 

Parsgnpl) 

Scope of this text__ 1 

Mental equipment neceesary for cryptanalytio work_ 2 

Validity of results of cryptanalysia.___ 2 

1. Scope of this text.—a. It is assumed that the student has studied the two preceding 
texts written by the same author and forming part of this series, viz, Elemeviary Military Cryp¬ 
tography, and Advanced Military Cryptography. These texts deal exclusively with cryptography 
as defined therein; that is, with the various types of ciphers and codes, their principles of con¬ 
struction, and their employment in cryptographing and decryptographing messages. Particular 
emphasis was placed upon such means and methods as are practicable for military usage. It is 
also assumed that the student has firmly in mind the technically precise, special nomenclature 
employed in those texts, for the terms and definitions therein will all be used in the present text, 
with essentially the same significances. If this is not the case, it is recommended that the student 
review his preceding work, in order to regain a familiarity with the specific meanings assigned 
to the terms used therein. There vriU be no opportunity herein to repeat this information and 
unless he understands clearly the significance of the terms employed, his progress will be retarded. 

b. This text constitutes the first of a series of texts on crypianalysis. Although most of the 
information contained hereon is applicable to cryptograms of various types and sources, special 
emphasis will he laid upon the prindples and methods of solving nulitaiy cryptograms. Ibtcept 
for an introductory discussion of fundamental principles underlying the science of cryptanalytics, 
this first text in the series will deal solely with the principles and methods for the analysis of 
monoalphabetic substitution ciphers. Even wi& this limitation it vriU be possible to ^scuss 
only a few of the many variations of this one type; but with a firm grasp upon the general prin¬ 
ciples no difficulties should be experienced with any variations that may be encountered. 

c. This and some of the succeedii^ texts will deal only with elementary types of cipher 
systems not because they may be encountered in militaiy operations but because their study is 
essential to an understanding of the principles underlying the solution of the modem, very much 
more complex types of ciphers and codes that are likely to be employed by the larger govern¬ 
ments today in the conduct of their military affairs in tune of war. 

d. All of this series of texts will deal only with the solution of visible secret writing. At 
some future date, texts dealii^ with the solution of invisible secret writmg, and with secret 
signalling systems, may be prepared. 

2. Mental equipment necessary for cryptanalytic work.— a. Captain Parker Hitt, in the 
first United States Army manual ‘ dealing with cryptography, opens the first chapter of his 
valuable treatise with the following sentence: 

Success in dealing with unknown ciphers is measured by these four things in the order named: perseverance, 
careful methods of analysts, intuition, luck. 

'■" _a. !> I 

* Hitt, Capt. Parker, Manual for the Solution of Military Ciphers. Army Service Schools Press, Fort Leaven¬ 
worth, Kansas, 1916. 2d Edition, 1918. (Both out of print.) 

( 1 ) 




2 


These words are as true today as they were then. There is no royal road to success in the 
solution of cryptograms. Hitt goes on to say; 

Cipher work will have little permanent attraction for one who expects results at once, without labor, for 
there is a vast amount of purely routine labor in the preparation of frequency tables, the rearrangement of 
ciphers for examination, and the trial and fitting of letter to letter before the message begins to appear. 

The present author deems it advisable to add that the kind of work involved in solAung 
cryptograms is not at all similar to that involved in solving “cross-word puzzles”, for example. 
The wide vogue the latter have had and continue to have is due to the appeal they make to the 
quite common instinct for mysteries of one sort or another; but in solving a cross-word puzzle 
there is usually no necessity for performing any preliminary labor, and palpable results become 
evident after the first minute or two of attention. This successful start spurs the cross-word 
“addict” on to complete the solution, which rarely requires more than an hour's time. Further¬ 
more, cross-word puzzles are all alike in basic principle and once imderstood, there is no more to 
learn. Skill comes largely from the embellishment of one’s vocabulary, though, to be sure, con¬ 
stant practice and exercise of the imagination contribute to the ease and rapidity with which 
solutions are generally reached. In solving cryptograms, however, many principles must be 
learned, for there are many different systems of varying degrees of complexity. Even some of 
the simpler varieties require the preparation of tabulations of one sort or another, which many 
people find irksome; moreover, it is only toward the very close of the solution that results in the 
form of intelli^ble text become evident. Often, indeed, the student will not even known whether 
he is on the right track imtil he has performed a large amount of prehminary “spade work” 
involving many hours of labor. Thus, without at least a willingness to pursue a fair amoimt of 
theoretical study, and a more than average amount of patience and perseverance, little skill and 
experience can be gained in the rather difficult art of cryptanalysis. General Givierge, the author 
of an excellent treatise on cryptanalysis, remarks in this connection: * 

The cryptanalyst’s attitude must be that of William the Silent: No need to hope in order to undertake, nor 
to succeed in order to persevere. 

h. As regards Hitt’s reference to careful methods of analysis, before one can be said to be a 
cryptanalyst worthy of the name it is necessary that one should have firstly a sound knowledge 
of the basic principles of cryptanalysis, and secondly, a long, varied, and active practical experi¬ 
ence in the successful application of those principles. It is not sufficient to have read treatises 
on this subject. One month’s actual practice in solution is worth a whole year’s mere reading 
of theoretical principles. An exceedingly important element of success in solving the more 
intricate ciphers is the possession of the rather unusual mental faculty designated in general 
terms as the power of inductive and deductive reasoning. Probably this is an inherited rather 
than an acquired faculty; the best sort of training for its emergence, if latent in the individual, 
and for its development is the study of the natural sciences, such as chemistry, physics, biology, 
geology, and the like. Other sciences such as linguistics and philology are also excellent. Apti¬ 
tude in mathematics is quite important, more especially in the solution of ciphers than of codes. 

c. An active imagination, or perhaps what Hitt and other writers call intuition, is essential, 
but mere imagination uncontrolled by a judicious spirit will more often be a hindrance than a 
help. In practical cryptanalysis the imaginative or intmtive faculties must, in other words, be 
guided by good judgment, by practical experience, and by as thorough a knowledge of the general 
situation or extraneous circumstances that led to the sending of the cryptogram as is possible 
to obtain. In this respect the many cryptograms exchanged between correspondents whose 
identities and general affairs, commercial, social, or political, are known are far more readily 

’ Givierge, G6n6ral Marcel, Cours de Cryptographie, Paris, 1926, p. 301. 


3 


solved than are isolated cryptograms exchanged between unknown correspondents, dealing with 
unknown subjects. It is obvious that in the former case there are good data upon which the 
intuitive powers of the cryptamalyst can be brought to bear, whereas in the latter case no such 
data are available. Consequently, in the absence of such data, no matter how good the imagina¬ 
tion and intuition of the cryptanalyst, these powers are of no particular service to him Some 
writers, however, regard the intuitive spirit as valuable from still another viewpoint, as may be 
noted in the following: ® 

Intuition, like a flash of lightning, lasts only for a second. It generally conies when one is tormented by 
a difiScult decipherment and when one reviews in his mind the fruitless experiments already tried. Suddenly 
the light breaks through and one finds after a few minutes what previous days of labor were unable to reveal. 

This, too, is true, but unfortunately there is no way in which the intuition may be sum¬ 
moned at will, when it is most needed.* There are certain authors who regard as indispensable 
the possession of a somewhat rare, rather mysterious faculty that they designate by the word 
“flair”, or by the expression “cipher brains.” Even so excellent an authority as General 
Givierge,® in referring to this mental facility, uses the following words: “Over and above per¬ 
severance and this aptitude of mind which some authors consider a special gift, and which they 
call intuition, or even, in its highest manifestation, clairvoyance, cryptographic studies will 
continue more and more to demand the qualities of orderliness and memory.” Although the 
present author beheves a special aptitude for the work is essential to cryptanalytic success, he is 
sure there is nothing mysterious about the matter at all. Special aptitude is prerequisite to 
success in all fields of endeavor. There are, for example, thousands of physicists, hundreds of 
excellent ones, but only a handful of world-wide fame. Should it be said, then, that a physicist 

♦ Lange et Soudart, Traits de Cryptographie, Librairie F61ix Alcan, Paris, 1926, p. 104. 

* The following extracts are of interest in this connection: 

The fact that the scientific investigator works 60 per cent of his time by non-rational means is, it seems, quite 
insufficiently recognized. There is without the least doubt an instinct for research, and often the most succe^ul 
investigators of nature are quite unable to give an account of their reasons for doing such and such an experi¬ 
ment, or for placing side by side two apparently unrelated facts. Again, one of the most salient traits in the 
character of the successful scientific worker is the capacity for knowing that a point is proved when it would not 
appear to be proved to an outside intelligence functioning in a purely rational manner; thus the investigator 
feels that some proposition is true, and proceeds at once to the next set of experiments without waiting and wasting 
time in the elaboration of the formal proof of the point which heavier minds would need. Questionless such a 
scientific intuition may and does sometimes lead investigators astray, but it is quite certain that if they did 
not widely make use of it, they would not get a quarter as far as they do. Experiments confirm each other, and a 
false step is usually soon discovered. And not only by this partial replacement of reason by intuition does the 
work of science go on, but also to the born scientific worker—and emphatically they cannot be made—the struc¬ 
ture of the method of research is as it were given, he cannot explain it to you, though he may be brought to agree 
a poetiori to a formal logical presentation of the way the method works.—Excerpt from Needham, Joseph, 
The Sceptical Biologist, London, 1929, p. 79. 

The essence of scientific method, quite simply, is to try to see how data arrange themselves into causal 
configurations. Scientific problems are solved by collecting data and by “thinking about them all the time.” 
We need to look at strange things until, by the appearance of known configurations, they seem familiar, and to 
look at familiar things until we see novel configurations which make them appear strange. We must look at 
events until they become luminous. That is scientific method . . . Insight is the touchstone . . . The appli¬ 
cation of insight as the touchstone of method enables us to evaluate properly the role of imagination in scientific 
method. The scientific process is akin to the artistic process: it is a process of selecting out those elements of 
experience which fit together and recombining them in the mind. Much of this kind of research is simply a cease¬ 
less mulling over, and even the physical scientist has considerable need of an armchair . . , Our view of scien¬ 
tific method as a struggle to obtain insight forces the admission that science is half art . . . Insight is the 
Unknown quantity which has eluded students of scientific method.—Excerpts from an article entitled Insiqht and 
Scientific Method, by Willard Waller, in The American Journal of Sociology, Vpl. XL, 1934, 

• Op. cU., p. 302. 


4 


who has achieved very notable success in his field has done so because he is the fortunate posesssor 
of a mysterious faculty? That he is fortunate in possessing a special aptitude for his subject is 
granted, but that there is anything mysterious about it, partaking of the nature of clairvoyance 
(if, indeed, the latter is a reality) is not granted. Wliile the ultimate nature of any mental 
process seems to be as complete a mystery today as it has ever been, the present author would 
like to see the superficial veil of mystery removed from a subject that has been shrouded in 
mystery from even before the Middle Ages down to our own times. (The principal and easily 
understandable reason for this is that governments have always closely guarded cryptographic 
secrets and anything so guarded soon becomes “mysterious.”) He would, rather, have the 
student approach the subject as he might approach any other science that can stand on its own 
merits with other sciences, because cryptanalytics, like other sciences, has a practical importance 
in human affairs. It presents to the inquiring mind an interest in its own right as a branch of 
knowledge; it, too, holds forth many difficulties and disappointments, and these are all the more 
keenly felt when the nature of these difficulties is not understood by those unfamiliar with the 
special circumstances that very often are the real factors that led to success in other cases. 
!^ally, just as in the other sciences wherein many men labor long and earnestly for the true 
satisfaction and pleasure that comes from work well-done, so the mental pleasure that the 
successful cryptanalyst derives from his accomplishments is very often the only reward for much 
of the drudgery Uiat he must do in his daily work. (General Givieige’s words in this connection 
are well worth quoting:* 

Some studies will last for years before bearing fruit. In the case of others, cryptanalysts undertaking them 
never get any result. But, for a cryptanalyst who likes the work, the Joy of discoveries efifaces the memory of his 
hours of doubt and impatience. 

d. With his usual deft touch, Hitt says of the element of luck, as regards the role it plays in 
analysis: 

As to luck, there is the old miners' proverb: “Gold is where you find it.” 

The cryptanalyst is lucky when one of the correspondents whose ciphers he is studying 
makes a blunder that gives the necessary clue; or when he finds two cryptograms identical in 
text but in different keys in the same system; or when he finds two cryptograms identical in 
text but in different systems, and so on. The element of luck is there, to be sure, but the crypt¬ 
analyst must be on the alert if he is to profit by these lucky “breaks.” 

e. If the present author were asked to state, in view of the progress in the field since 1916, 
what elements might be added to the four ingredients Hitt thought essential to cryptanalytic 
success, he would be inclmed to mention the following: 

(1) A broad, general education, embodying interests covering as many fields of practical 
knowledge as possible. This is useful because the cryptanalyst is often called upon to solve 
messages dealing with the most varied of human activities, and the more he knows about these 
activities, the easier his task. 

(2) Access to a large library of current literature, and wide and direct contacts with sources 
of collateral information. These often afford clues as to the contents of specific messages. For 
example, to be able instantly to have at his disposal a newspaper report or a personal report of 
events described or referred to in a message under investigation goes a long way toward simpli¬ 
fying or facilitating solution. Government cryptanalysts are sometimes fortunately situated in 
this respect, especially where various agencies work in harmony. 

(3) Proper coordination of effort. This includes the organization of cryptanalytic persormel 
into harmonious, efficient teams of cooperating individuals. 

• Op. cU., p. 301, 


5 


(4) Under mental equipment he would also include the faculty of being able to concentrate 
on a problem for rather long periods of time, without distraction, nervous irritability, and 
impatience. The strain rmder which cryptanalytic studies are necessarily conducted is quite 
severe and too long-continued application has the effect of draining nervous energy to an 
unwholesomiB degree, so that a word or two of caution may not here be out of place. One should 
continue at work only so long as a peaceful, calm spirit prevails, whether the work is fruitful or 
not. But just as soon as the mind becomes wearied with the exertion, or just as soon as a feeling 
of hopelessness or mental fatigue intervenes, it is better to stop completely and tmm to other 
activities, rest, or play. It is essential to remark that systematization and orderliness of work 
are aids in reducing nervous tension and irritability. On this account it is better to take the 
time to prepare the data carefully, rewrite the text if necessary, and so on, rather than work 
with riipshod, incomplete, or improperly arranged material. 

(5) A retentive memory is an important asset to cryptanalytic skill, especially in the solu¬ 
tion of codes. The ability to remember individual groups, their approximate locations in other 
messages, the associations they form with other groups, their peculiarities and similarities, saves 
much wear and tear of the mental machinery, as well .as much time in looking up these groups in 
indexes. 

/. It may be advisable to add a word or two at this point to prepare the student to expect 
slight mental jars and tensions which will almost inevitably come to him in the conscientious 
study of this and the subsequent texts. The present author is well aware of the complaint of 
students that authors of texts on cryptanalysis base much of their explanation upon their fore¬ 
knowledge of the “answer”—^which the student does not know while he is attempting to follow 
the solution with tm unbiased mind. They complain too that these authors use such expressions 
as “obviously”, “naturally”, “of course”, “it is evident that”, and so on, when the circumstances 
seem not at all to warrant their use. There is no question but that this sort of treatment is apt 
to discourage the student, especially when the point elucidated becomes clear to him only after 
many hours’ labor, whereas, according to the book, the author noted the weak spot at the first 
moment’s inspection. The present author can only promise to try to avoid making the steps 
appear to be much more simple than they really are, and to suppress glaring instances of imjusti- 
fiable “jumping at conclusions.” At the same time he must indicate that for pedagogical reasons 
in many cases a message has been consciously “manipulated” so as to allow certain principles to 
become more obvious in the illustrative examples than they ever are in practical work. During 
the course of some of the explanations attention wUl even be directed to cases of unjustified 
inferences. Furthermore, of the student who is quick in observation and deduction, the author 
will only ask that he bear in mind that if the elucidation of certain principles seems prolix and 
occupies more space than necessary, this is occasioned hy the author’s desire to carry the 
explanation forward in very short, easily-comprehended, and plainly-described steps, for the 
benefit of students who are perhaps a bit slower to grasp but who, once they understand, are 
able to retain and apply principles slowly learned just as well, if not better than the students 
who learn more quickly. 

3. Validity of results of cryptanalysis.—^Valid, or authentic cryptanalytic solutions cannot 
and do not represent “opinions” of the cryptanalyst. They are valid only so far as they are 
wholly objective, and are susceptible of demonstration and proof, employing authentic, objective 
methods. It should hardly be necessary (but an attitude frequently encountered among laymen 
makes it advisable) to indicate that the validity of the results achieved by any serious crypt¬ 
analytic studies on authentic material rests upon the same sure foundations and are reached by 
the same general steps as the results achieved by any other scientific studies; viz, observation, 
hypothesis, deduction and induction, and confirmatory experiment. Implied in the latter is the 







6 


possibiHty that two or more qualified investigators, each working independently upon the same 
material, will achieve identical (or practically identical) results. Occasionally a pseudo-crypt¬ 
analyst offers “solutions” which cannot withstand such tests; a second, unbiased, investigator 
working independently either cannot conaistenlly apply the methods alleged to have been applied 
by the pseudo-cryptanalyst, or eke, if he can apply them at all, the results (plam-text transla¬ 
tions) are far different in the two cases. The reason for this is that in such cases it is generally 
found that the “methods” are not clear-cut, straightforward or mathematical m character. 
Instead,, they often involve the making of judgments on matters too tenuous to measure, we^h, 
or otherwise subject to careful scrutiny. In such cases, the conclusion to which the unprejudiced 
observer is forced to come is that the alleged “solution” obtained by the first investigator, the 
pseudo-cryptanalyst, is purely subjective. In nearly all cases where this 1ms happened (and they 
occur from time to time) there has been uncovered nothing which can in any way be used to 
impugn the integrity of the pseudo-cryptanalyst. The worst that can be smd of him is that he 
has become a victim of a special or peculiar form of self-delusion, and that his desire to solve the 
problem, usually in accord with some previously-formed opinion, or notion, has over-balanced, 
or undermined, his judgment and good sense.’' 

’ Specific reference can be made to tbe following typical “case histories”: 1 

Donnelly, Ignatius, The Great Cryptogram. Chicago, 1888. 

OWTO, Orville W., Sir Fremeie Bacon’» Cipher Story. Detroit, 1895. 

'Gallup, Elizabeth Wells, Francis Bacon’s Biliteral Cipher. Detroit, 1900. 

Muig nlioiith, D. S.. The Homer of AristMe. Oxford, 1923. ^ 

N^old, William Romaine, The Cipher of Roger Bacon. Philadelphia, 1928. (For a scholarly and 
complete demoUtion of Professor Newbold’s work, see an article entitled Roger Bacon and 
the Voynich MS, by John M. Manly, in Speculum, Vol. VI, No. 3, July 1931.) 

Arensberg, Walter Conrad, The Cryptography of Shakespeare. Los Angeles, 1922. 

The Shakespearean Mystery. Pittsburgh, 1928. 

The Baconian Keys. Pittsburgh, 1928. 

Feely, Joseph Martin, The Shakespearean Cypher. Rochester, N. Y., 1931. 

Deciphering Shakespeare. Rochester, N. Y., 1934. 


Section II 


FUNDAMENTAL PRINCIPLES 

Paragraph 


The four basic operations in cryptanalysis...-. 4 

The determination of the language employed. 6 

The determination of the general system. 6 

The reconstruction of the specific key. 7 

The reconstruction of the plain text. 8 


4. The four basic operations in cryptanalysis.— a. The solution of practically every ciypto- 
gram involves four fundamental operations or steps: 

(1) The determination of the language employed in the plain-text version. 

(2) The determination of the general system of cryptography employed. 

(3) The reconstruction of the specific key in the case of a cipher system, or the reconstruc¬ 
tion, partial or complete, of the code book, in the case of a code system; or both, in the case of an 
enciphered code system. 

(4) The reconstruction or establishment of the plain text. 

b. These operations will be taken up in the order in which they are given above and in which 
they usually are performed in the solution of cryptograms, although occasionally the second 
step may precede the first. 

6. The determination of the language employed.— a. There is not much that need be said 
with respect to this operation except that the determination of the language employed seldom 
comes into question in the case of studies made of the cryptograms of an organized enemy. 
By this is meant that during wartime the enemy is of course known, and it follows, therefore, 
that the language he employs in his messages will almost certainly be his native or mother tongue. 
Only occasionally nowadays is this rule broken. Formerly it often happened, or it might have 
indeed been the general rule, that the language used in diplomatic correspondence was not the 
mother tongue, but French. In isolated instances during the World War, the Germans used 
English when their own language could for one reason or another not be employed. For example, 
for a year or two before the entry of the United States into that war, during the time America 
was neutral and the German Government maintained its embassy in Washington, some of the 
messages exchanged between the Foreign Office in Berlin and the Embassy in Washington were 
cryptographed in English, and a copy of the code used was deposited with the Department of 
State and our censor. Another instance is found in the case of certain Hindu conspirators who 
were associated with and partially financed by the German Government in 1915 and 1916; they 
employed English as the language of their cryptographic messages. Occasionally the crypto¬ 
grams of enemy agents may be in a language different from that of the enemy. But in general 
these are, as has been said, isolated instances; as a rule, the language used in cryptograms ex¬ 
changed between members of large organizations is the mother tongue of the correspondents. 
Where this is not the case, that is, when cryptograms of unknown origin must be studied, the 
cryptanalyst looks for any indications on the cryptograms themselves which may lead to a 
conclusion as to the language employed. Address, signature, and plain-language words in the 
preamble or in the body of the text all come under careful scrutiny, as well as all extraneous 
circumstances connected with the manner in which the cryptograms were obtained, the person 
on whom they were found, or the locale of their origin and destination. 

( 7 ) 


















8 


d 


b. In special cases, or under special circumstances a clue to the language employed is found 
in the nature and composition of the cryptographic text itself. For example, if the letters K and 
W are entirely absent or appear very rarely in messages, it may indicate that the language is 
Spanish, for these letters are absent in the alphabet of that language and are used only to spell 
foreign words or names. The presence of accented letters or letters marked with special signs of 
one sort or another, peculiar to certain languages, will sometimes indicate the language used. 
The Japanese Morse telegraph alphabet and the Kussian Morse telegraph alphabet contain 
combinations of dots and dashes which are peculiar to those alphabets and thus the interception 
of messages containing these special Morse combinations at once indicates the language involved. 
Finally, there are certain peculiarities of alphabetic languages which, in certain t 3 rpe 8 of crypto¬ 
grams, viz, pme transposition, give clues as to the language used. For example, the frequent 
digraph C H, in German, leads to the presence, in cryptograms of the type mentioned, of many 
isolated C’s and H’s; if this is noted, the cryptogram may be assumed to be in German. 

e. In some cases it is perfectly possible to perform certain steps in cryptanalysis before 
the language of the cryptogram has been definitely determined. Frequency studies, for example, 
may be made and analytic processes performed without this knowledge, and by a cryptanalyst 
wholly unfamiliar with the language even if it has been identified, or who knows only enough 
about the language to enable him to recognize valid combinations of letters, syllables, or a few 
conunon words in that language. He may, after this, call to his assistance a translator who may 
not be a cr 3 nptanalyst but who can materially aid in making necessary assumptions based upon 
his special knowledge of the characteristics of the language in question. Thus, cooperation 
between cryptanalyst and translator results in solution.* 

6. The determination of the general system.—a. Except in the case of the more simple 
types of cryptograms, the determination of the general system according to which a given crypto¬ 
gram has ^en produced is usually a difficult, if not the most difficult, step in its solution. The 
reason for this is not hard to find. 

b. As will become apparent to the student as he proceeds with his study, in the final analysis, 
the solution of every cryptogram involving a form of substitution depends upon its reduction to mono- 
alphabetic terms, if it is not originally in those terms. This is true not only of ordinary substitution 
ciph^, but also of combined substitution-transposition ciphers, and of enciphered code. If the 
cryptogram must be reduced to monoalphabetic terms, the manner of its accomplishment is 
usually indicated by the cryptogram itself, by external or internal phenomena which become 
apparent to the cryptanalyst as he studies the cryptogram. If this is impossible, or too difficult 
the cryptanalyst must, by one means or another, discover how to accomplish this reduction, 
by bringing to bear all the special or collateral information he can get from all the sources at his 
command. If both these possibilities fail him, there is little left but the long, tedious, and often 
fruitless process of elimination. In the case of transposition ciphers of the more complex type, 
the discovery of the basic method is often simply a matter of long and tedious elimination of 
possibilities. For cryptanalysis has unfortimately not yet attained, and may indeed never 
attain, the precision found today in qualitative analysis in chemistry, for example, where the 
analytic process is absolutely clear cut and exact in its dichotomy. A few words in explanation of 
what is meant may not be amiss. When a chemist seeks to determine the identity of an unknown 

' The writer has seen in print statements that “during the World War . . . decoded messages In Japanese 
and Russian without knowing a word of either language.” The extent to which such statements are exaggerated 
will soon become obvious to the student. Of course, there are occasional Instances in which a mere clerk with 
quite limited experience may be able to “solve” a message in an extremely simple system in a language of which 
he has no knowledge at all; but such a “solution” calls for nothing more arduous than the ability to recognize 
pronounceable combinations of vowels and consonants—an ability that hardly deserves to be rated as “crypt- 
analytic” in any real sense. To say that it is possible to solve a cryptogram in a foreign language “without 
knowing a word of that language” is not quite the same as to say that it is possible to do so with only a slight 
knowledge of the language; and it may be stated without cavil that the better the cryptanalyst’s knowledge of 
the language, the greater are the chances for his success and, in any case, the easier is his work. 


substance, he applies certain specific reagents to the substance and in a specific sequence. The 
first reagent tells h i m definitely into which of two primary classes the unknown substance falls. 
He then applies a second test with another specific reagent, which tells him again quite definitely 
into which of two secondary classes the unknown substance falls, and so on, until finally he has 
reduced the unknown substance to its simplest terms and has found out what it is. In striking 
contrast to this situation, cryptanalysis affords exceedingly few “reagents” or tests that may be 
applied to determine positively that a given cipher belongs to one or the other of two systems 
yielding externally similar results. And this is what makes the analysis of an isolated, complex 
cryptogram so difficult. Note the limi ting adjective “isolated” in the foregoing sentence, for it 
is xised advisedly. It is not often that the general system fails to disclose itself or cannot be 
discovered by painstaking investigation when there is a great volmne of text accumulating from 
a regular traffic between numerous correspondents in a large oiganization. Sooner or later the 
system becomes known, either because of blunders and carelessness on the part of the personnel 
entrusted with the cryptographing of the messages, or because the accumulation of text itself 
makes possible the determination of the general system by ciyptanalytic studies. But in the 
case of a single or even a few isolated cryptograms concerning which little or no information can 
be gained by the cryptanalyst, he is often unahle, without a knowledge of, or a shrewd guess as to 
the general system employed, to decompose the heterogeneous text of the cryptogram into 
homogeneous, monoalphabetic text, which is the ultimate and essential step in analysis. The 
only knowledge that the cryptanalyst can bring to bis aid in this most difficult step is that gained 
by long experience and practice in the analysis of many different types of systems. 

c. On account of the complexities surrounding this particular phase of cryptanalysis, and 
because in any scheme of analysis based upon succesrive eliminations of alternatives the crypt¬ 
analyst can only progress so far as the extent of his own knowledge of all the possible alternatives 
will permit, it is necessary that detailed discussion of the eliminative process be postponed until 
the student has covered most of the field. For example, the student will perhaps want to know 
at once how he can distinguish between a cryptogram that is in code or enciphered code from one 
that is in cipher. It is at this stage of his studies impracticable to give him any helpful indica¬ 
tions on his question. In return it may be asked of him why he should expect to be able to do 
this in the early stages of his studies when often the experienced expert cryptanalyst is baffled on 
the same score I 

d. Nevertheless, in lieu of more precise tests not yet discovered, a general guide that may be 
useful in cryptanalysis will be built up, step by step as the student progresses, in the form of a 
series of charts comprising w;hat may be designated An Analytical Key For Cryptanalysis. (See 
Par. SO.) It may be of assistance to the student if, as he proceeds, he will carefully study the 
charts and note the place which the particular cipher he is solving occupies in the general crypt- 
analytic panorama. These charts admittedly constitute only very brief outlines, and can 
therefore be of but little direct assistance to him in the analysis of the more complex types of 
ciphers he may encounter later on. So far as they go, however, they may be foxmd to be quite 
useful in the study of elementary cryptanalysis. For the experienced cryptanalyst they can 
serve only as a means of assuring that no possible step or process is inadvertently overlooked m 
attempts to solve a difficult cipher. 

e. Much of the labor involved in cryptanalytic work, as referred to in Par. 2, is connected 
with this determination of the general system. The preparation of the text, its rewriting in 
different forms, sometimes being rewritten in a half dozen ways, the recording of letters, the 
establishment of frequencies of occurrences of letters, comparisons and experiments made with 
known material of similar character, and so on, constitute much labor that is most often in¬ 
dispensable, but which sometimes turns out to have been wholly unnecessary, or in vain. In a 









10 


tecent treatise * it is stated quite boldly that “this work once done, the determination of the 
system is often relatively easy.” This statement can certainly apply only to the simpler types of 
ciphers; it is entirely misleading as regards the much more frequently encountered complex 
cryptograms of modem times. 

7. The reconstruction of the specific key.— a. Nearly all practical cryptographic methods 
require the use of a specific key to guide, control, or modify the various steps under the general 
system. Once the latter has been disclosed, discovered, or has otherwise come into the possession 

j of the cryptanalyst, the next step in solution is to determine, if necessary, and if possible, the 

j specific key that was employed to cryptograph the message or messages imder examination. 

' This determination may not be in complete detail; it may go only so far as to lead to a knowledge 

I of the number of alphabets involved in a substitution cipher, or the number of colunms involved 

j in a transposition cipher, or that a one-part code has been used, in the case of a code system, 

f But it is often desirable to determine the specific key in as complete a form and with as much 

I detail as possible, for this information wiU very frequently be useful in the solution of subsequent 

I cryptograms exchanged between the same correspondents, since the nature of the specific key 

in a solved case may be expected to give clues to the specific key in an imsolved case. 

b. Frequently, however, the reconstruction of the key is not a prerequisite to, and does not 
cbhstitute an absolutely necessary preliminary step in, the fourth basic operation, viz, the recon- 
stniction Oir estabMiment of the plain text. In many cases, indeed, the two processes are 
carried along simultaneously, the one assisting the other, until in the final stt^es both have been 
completed in entireties. In still other cases the reconstruction of the specific key may 
succeed instead of precede the reconstruction of the plain text, and is accomplished purely as a 
!' matter of academic interest; or the specific key may, in unusual cases, never be reconstructed. 

8 . The reconstruction of the plain text.— a. little need be said at this point on this phase 

=!; of cijptanalysis. The process usually consists, in the case of substitution ciphers, in the estab¬ 

lishment of equivalency between specific letters of the cipher text and the plain text, letter by 
letter, pair by pair, and so on, depending upon the particular type of substitution system 
involved. In the case of transposition ciphers, the process consists in rearranging the elements of 
the cipher text, letter by letter, pair by pair, or occasionally word by word, depending upon the 
particular type of transposition system involved, until the letters or words have been returned 
to their original plain-text order. In the case of code, the process consists in determining the 
meaning of each code group and inserting this meaning in the code text to reestablish the original 
plain text. 

b. Hie foregoing processes do not, as a rule, begin at the beginning of a message and 
continue letter by letter, or group by group in sequence up to the very end of the message. The 
establishment of values of cipher letters in substitution methods, or of the positions to which 
cipher letters should be transferred to form the plain text in the case of transposition methods, 
comes at very irregular intervals in the process. At first only one or two values scattered here 
and there throughout the text may appear; these then form the “skeletons” of words, upon which 
further work, by a continuation of the reconstruction process, is made possible; in the end the 
complete or nearly complete ® text is established. 

c. In the case of cryptograms in a foreign language, the translation of the solved messages 
is a final and necessary step, but is not to be considered as a cryptanalytic process. However, 
it is commonly the case that the translation process will be carried on simultaneously with the 
cryptanalytic, and will aid the latter, especially when there are lacunae which may be filled in 

j from the context. (See also Par. 5c in this connection.) 

I » Lange et Soudart, op. cit., p. 106. 

• Sometimes in the case of code, the meaning of a few code groups may be lacking, because there is insufficient 
I text to establish their meaning. 


Section III 

FREQUENCY DISTRIBUTIONS 


The simple or uniliteral frequency distribution.. Pwagmp^ 

Important features of the normal uniliteral frequency distributiom„""Z^”.”"Z”!"™”"'' ” 10 

Constancy of the standard or normal uniliteral frequency distribution_. H 


8 . The simple or uniUteral frequency distribution.—«. It has long been known to cryptog¬ 
raphers and typographers that the letters composing the words of any intelligible written text 
composed in any language which is alphabetic in construction are employed with greatly vwying 
frequencies. For example, if on cross-section paper a simple tabulation, shown in Fig. 1, called a 
unilUeral frequency dutrihviion, is made of the letters composing the words of the preceding sen¬ 
tence, the variation in frequency is strikingly demonstrated. It is seen that whereas certain 
letters, such as A, E, I, N, 0, R, S, and T, are employed very frequently, other letters, such as 
C, G, P, and W are employed not nearly so frequently, while stiU other letters, such as F, J Q V 
and Z are employed either seldom or not at all. » » > > 

I == ^ 

5 ^ g g § $ g 

I ggg § ggg ^ 

g 5 g 5 g = g g g ... g 5ggg~,ggg§...g..,g 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

U a 8 4 22 2 g 10 16 0 1 » 3 17 14 8 1 13 10 20 3 1 4 1 7 0 

(Total=200 letters) 

FlQtIB* 1. 

b. If a similar tabulation is now made of the letters comprising the words of the second 
sentence in the preceding paragraph, the graph shown in Fig. 2 is obtained. Both sentences 
have exactly the same number of letters ( 200 ). 

■ g 

g g 

*= ^ S gg 

g55=g=: g §gg...ggg 

g = ggggggg '-ggggg = gggg...5:_S 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

12 2 8 7 26 7 4 6 20 0 1 86 17 14 6 2 13 14 17 6 1 2 1 30 

(Total=200 lettete) 

Fiodbi 2, 

e. J^hough each of these two graphs exhibits great variation in the relative frequencies 
with which difererU letters are employed in the respective sentences to which they apply, no 
mark^ differences are exhibited between the frequencies of the same letter in the two graphs. 
Conapare, for example, the frequencies of A, B, C . . . Z in Fig. 1 with those of A, B, C, . . . Z 
in Fig. 2. Aside from one or two exceptions, as in the case of the letter F, these two graphs agree 
rather strikingly. 


( 11 ) 





12 


d. This agreement, or similarity, would be practically complete if the two texts were much 
longer, for example, five times as long. In fact, when two texts of similar character, each con¬ 
taining more than 1,000 letters, are compared, it would be found that the respective frequencies 
of the 26 letters composing the two graphs show only very slight differences. This means, in 
other words, that in normal text each letter of the ^phabet occurs with a rather constavi or 
eharacteristie frequency which it tends to approximate, depending upon the length of the text 
analyzed. The loiter the text (within certain limits), the closer will be the approximation.* 

e. An experiment along these lines will be convincing. A series of 260 official telegrams * 
passing through the War Department Message Center was examined statistically. The mes¬ 
sages were divided into five sets, each totaling 10,000 letters, and the five distributions shown 
in Table 1-A, were obtained. 

J. If the five distributions in Table 1-A are summed, the results are as shown in Table 2-A. 


Tablk 1-A.— Absolute frequencies of letters appearing in five sets of Oovemmental plain4ext tele¬ 
grams, each set containing 10,000 letters, arranged alphaheiicaUy 



• See footnote 6, page 16. 

* These comprised m^isages from several departments in addition to the War Department and were all of 
an administrative character. 


13 


Table 2-k.—Absolute frequencies of letters appearing in the comUned five sets of messages totaling 
50,000 letters, arranged alphabetieaUy 


A.... 

- 3,683 

G.... 

819 

L.... 

- 1 ,821 

Q-. 

175 

V...... 

766 

B.... 

487 

H.... 

- 1,694 


- 1 ,237 

R-... 

- 3,788 

W...... 

780 

C.... 

. 1,534 

I.... 

- 3,676 

N..... 

.. 3,975 

S. 

.. 3,058 

X. 

231 

D.-._ 

- 2, 122 

J.... 

82 

0.... 

- 3,764 

T.... 

- 4,595 

Y 

967 

E. 

p 

. 6,498 

K..... 

148 


- 1 ,335 

U..... 

- 1,300 

Z._ 

49 


F...... 1,416 


g. The frequencies noted in subparagraph/, when reduced to the basis of 1,000 letters and 
then used as a basis for constructing a simple chart that will exhibit the variations in frequency 
m a stnkmg manner, yield the following graph which is hereafter designated as the mrmal, or 
standard unuiteral frequency distribution for English telegraphic plain text: 

g 

g 

g 

g 

g 

s 



10; Important features of the normal uniliteral frequency distribution.—a. When the graph 
shown in Fig. 3 is studied in detail, the following features are apparent: 

(1) It IS quite irregular in appearance. This is because the letters are used with greatly 
varying frequencies, as discussed in the preceding paragraph. This irregular appearance is often 
described by saying that the graph shows marked crests and troughs that is, points of high fre¬ 
quency and low frequency. 


148274—38-2 










































14 


(2) The relative positions in which the crests and troughs fall within the graph, that is, the 
spatial relations of the crests and troughs, are rather definitely fixed and are determined by cir¬ 
cumstances which have been explained in a preceding text.® 

(3) The relative heights and depths of the crests and troughs within the graph, that is, the 
linear extensions of the lines marking the respective frequencies, are also rather definitely fixed, 
as would be found if an equal volume of similar text were analyzed. 

(4) The most prominent crests are marked by the vowels A, E, I, 0, and the consonants 
N, R, S, T; the most prominent troughs are marked by the consonants J, K, Q, X, and Z. 

(5) The important data are summarized in tabular form in Table 3. 


Table 3 



Frequency 

Percent of 
total 

Percent of 
total in 
round 
numbers 

6 Vowels: A E I 0 U Y..______ 

398 

39.8 

40 

20 Consonants: 

5 High Frequency (D N R S T)...... 

350 

35.0 

35 

10 Medium Frequency (BCFGHLMPV W).... 

238 

23.8 

24 

5 Low Frequency (J K Q X Z)... 

14 

1.4 

1 

Total. 

1,000 

100.0 

100 


(6) The frequencies of the letters of the alphabet are as follows: 

A_ 74 G. 16 L_ 36 Q.. 3 V._ 15 

B_ 10 H_ 34 M. 25 R.. 76 W_ 16 

C_ 31 1. 74 N. 79 S_ 61 X. 5 

D.. 42 J. 2 0_ 75 T_ 92 Y. 19 

E_ 130 K_ 3 P-. 27 U. 26 Z. 1 

F. 28 

(7) The relative order of frequency of the letters is as follows: 

E_ 130 I..... 74 C. 31 Y_ 19 X. 5 

T_ 92 S.. 61 F-.... 28 "G._ 16 Q.. 3 

N.. 79 .D.. 42 *P... 27 W. 16 K.. 3 

R_ 76 L.. 36 U_ 26 V.. 15 .J.... 2 

,0... 75 H... 34 M_ 25 .B_ 10 Z.. 1 


(8) The four vowels A, E, I, 0 (combined frequency 353) and the four consonants N, R, S, T 
(combined frequency 308) form 661 out of every 1,000 letters of plain text; in other words, less 
than }i of the alphabet is employed in writing % of normal plain text. 

* Section VII, Elementary Military Cryptography. 


15 


h. The data given in Fig. 3 and Table 3 represent the relative frequencies foimd in a large 
volume of English telegraphic text of a governmental, administrative character. These fre¬ 
quencies will vary somewhat with the nature of the text analyzed. For example, if an equal 
number of telegrams dealing solely with commercial transactions in the leather industry were 
studied statistically, the frequencies would be slightly different because of the repeated occurrence 
of words peculiar to that industry. Again, if an equal number of telegrams dealing solely -with 
military messages of a tactical character were studied statistically, the frequencies would differ 
slightly from those found above for general governmental messages of an administrative character. 

c. If ordinary English literary text (such as may be found in any book, newspaper, or printed 
document) were analyzed, the frequencies of certain letters would be changed to an appreciable 
degree. This is because in telegraphic text words whieh are not strictly essential for intelligibility 
(such as the definite and indefinite articles, certain prepositions, conjunctions and pronouns) are 
omitted. In addition, certain essential words, such as “stop”, “period”, “comma”, and the like, 
which are usually indicated in written or printed matter by symbols not easy to transmit tele¬ 
graphically and which must, therefore, be spelled out in telegrams, occur very frequently. Fur¬ 
thermore, telegraphic text often employs longer and more uncommon words than does ordinary 
newspaper or book text. 

d. As a matter of fact, other tables eompiled in the Office of the Chief Signal Officer gave 
slightly different results, depending upon the source of the text. For example, three tables based 
upon 75,000, 100,000, and 136,257 letters taken from various sources (telegrams, newspapers, 
magazine articles, books of fiction) gave as the relative order of frequency for the fitrst 10 letters 
the following: 

For 75,000 letters.. ETRNIOASDL 

For 100,000 letters. ETRINOASDL 

For 136,257 letters. ETRNAOISLD 

Table 4 .—Frequency table for 10,000 letters of literary English, as compiled by Hitt 
ALPHABETICALLY ARRANGED 

A. ..... 778 G._ 174 L_ 372 Q.. 8 V- 112 

B. _ 141 H_ 595 M._ 288 R._ 651 W.- 176 

C_ 296 I_ 667 N. 686 S_ 622 X._ 27 

D.. 402 J... 51 0.807 T_ 855 Y.- 196 

E. 1 ,277 K.. 74 P. 223 U . 308 Z_ 17 

F...... 197 

ARRANGED ACCORDING TO FREQUENCY 

E. 1 ,277 R. 651 U. _ 308 Y..... 196 K.- 74 

T. 855 S_ 622 C. 296 W_ 176 J- 51 

0._ 807 H._ 595 M_ 288 G_ 174 X._ 27 

A.. 778 D_ 402 P_ 223 B_ 141 Z.- 17 

N. 686 L. 372 F. 197 V. 112 Q._ 8 

^ I._ 667 



















































































































16 


17 


Hitt also compiled data for telegraphic text (but does not state what kind of messages) and 
gives the following table: 


Table 5. —Frequency table for 10,000 letters of telegraphic English, as compiled by Hitt 
ALPHABETICALLY ARRANGED 


A._ 

813 

G.. 

. 201 

L. 

- 392 

Q..... 

_ 38 

V..... 

_ 136 

B 

149 

H 

3S6 

M 

.. 273 

R 

..... 677 

W 

166 

C. 

306 

I.. 

. 711 

N. 

.. 718 

S. 

_ 656 

X..... 

_ 51 

D 

417 

J 

42 

0 

.. 844 

T 

634 

Y 

208 

E. 

1 ,319 

K.. 

. 88 

P. 

.. 243 

U. 

. 321 

Z..... 

_ 6 

F._ 

205 












ARRANGED 

ACCORDING TO 

FREQUENCY 



E.. 

1 ,319 

S._ 

. 656 

U_ 

.. 321 

F. 

_ 205 

K...., 

_ 88 

0 

844 

T- 

634 

C. 

.. 306 

G 

201 

X_ 

_ 51 

A...... 

813 

D.. 

.. 417 

M.. 

.. 273 

W. 

..... 166 

J..... 

_ 42 

N_ 

718 

L.. 

392 

P. 

.. 243 

B 

149 

Q_ 

38 

I._ 

711 

H.. 

... 386 

Y. 

.. 208 

V. 

. 136 

Z..... 

_ 6 

R._ 

677 










e. Frequency data applicable purely to English military text were compiled by Hitt/ from 
a study of 10,000 letters taken from orders and reports. The frequencies found by him are given 
in Tables 4 and 5. 

11. Constancy of the standard or normal, uniliteral frequency distribution.— a. The 
relative frequencies disclosed by the statistical study of large volumes of text may be considered 
to be the standard or normal frequencies of the letters of written English. Counts made of 
smaller volumes of text will tend to approximate these normal frequencies, and, within certain 
limits,® the smaller the volume, the lower will be the degree of approximation to the normal, 
until, in the case of a very short message, the normal proportions may not obtain at all. It is 
advisable that the student fix this fact firmly in mind, for the sooner he realizes the true nature 
of any data relative to the frequency of occurrence of letters in text, the less often will his labors 
toward the solution of specific ciphers be thwarted and retarded by too strict an adherence to 
these generalized principles of frequency. He should constantly bear in mind that such data 
are merely statistical generalizations, that they will be found to hold strictly true only in large 
volumes of text, and that they may not even be approximated in short messages. 

b. Nevertheless the normal frequency distribution or the “normal expectancy” for any 
alphabetic language is, in the last analysis, the best guide to, and the usual basis for, the solution 
of cryptograms of a certain type. It is useful, therefore, to reduce the normal, uniliteral 
frequency distribution to a basis that more or less closely approximates the volume of text which 
the cryptanalyst most often encounters in individual cryptograms. As regards length of mes¬ 
sages, counting only the letters in the body, and excluding address and signature, a study of the 

* Op. cit., pp. 6-7. 

* It is useless to go beyond a certain limit in establishing the normal-frequency distribution for a given 
language. As a striking instance of this fact, witness the frequency study made by an indefatigable German, 
Kaeding, who in 1898 made a count of the letters in about 11,000,000 words, totaling about 62,000,000 letters in 
German text. When reduced to a percentage basis, and when the relative order of frequency was determined, 
the results he obtained differed very little from the results obtained by Kasiski, a German cryptographer, from a 
count of only 1,060 letters. See Kaeding, Haeufigkeitawoerterbuch, Steglitz, 1898; Kasiski, Die Oeheimschriften 
und die Dechiffrir-Kunst, Berlin, 1863. 


260 telegrams referred to in paragraph 9 shows that the arithmetical average is 217 letters; 
the statistical mean, or weighted average,® however, is 191 letters. These two results are, 
however, close enough together to warrant the statement that the average length of telegrams 
is approximately 200 letters. The frequencies given in Par. 9/ have therefore been reduced to 
a basis of 200 letters, and the following uniliteral frequency distribution may be taken as showing 
the most typical distribution to be expected in 200 letters of telegraphic English text: 

i 

g g g gg g5=g 

g ^5g ^g = gg gg g 
g^ggggsgg ggggg gggg55-,g 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

e. The student should take careful note of the appearance of the distribution ’’ shown in 
Fig. 4, for it will be of much assistance to him in the early stages of his study. The manner of 
setting down the tallies should be followed by him in making his own distributions, indicating 
every fifth occurrence of a letter by an oblique tally. This procedure almost automatically 
shows the total number of occurrences for each letter, and yet does not destroy the graphical 
appearance of the distribution, especially if care is taken to use approximately the same amount 
of space for each set of five tallies. Cross-section paper is very useful for this purpose. 

d. The word “unUiteral” in the designation “uniliteral frequency distribution” means 
“single letter”, and it is to be inferred that other types of frequency distributions may be encoun¬ 
tered. For example, a distribution of pairs of letters, constituting a biliteral frequency distri¬ 
bution, is very often used in the study of certain cryptograms in which it is desired that pairs 
made by combining successive letters be listed. A biliteral distribution of A B C D E F would 
take these pairs: AB, BC, CD, DE, EF. The distribution could be made in the form of a large 
square divided up into 676 cells. When distributions beyond biliteral are required (triliteral, 
quadraliteral, etc.) they can only be made by listing them in some order, for example, alpha¬ 
betically based on the Ist, 2d, 3d, . . . letter. 

‘ The arithmetical average is obtained by adding each different len^h and dividing by the number of 
different-length messages; the mean is obtained by multiplying each different length by the number of messages 
of that length, adding all products, and dividing by the total number of messages. 

’’ The use of the terms “distribution” and “frequency distribution”, instead of “table” and “frequency 
table”, respectively, is considered advisable from the point of view of consistency with the usual statistical 
nomenclature. When data are given in tabular form, with frequencies indicated by numbers, then they may 
properly be said to be set out in the form of a table. When, however, the same data are distributed in a chart 
which partakes of the nature of a graph, with the data indicated by horizontal or vertical linear extensions, or 
by a curve connecting points corresponding to quantities, then it is more proper to call such a graphic represen¬ 
tation of the data a distribution. 




























































19 


Section IV 

FUNDAMENTAL USES OF THE UNILITERAL FREQUENCY DISTRIBUTION 

Paragraph 

The four facta which can be determined from a study of the uniliteral frequency distribution for a crypto¬ 


gram..-... 12 

Determining the class to which a cipher belongs... 13 

Determining whether a substitution cipher is monoalphabetic or polyalphabetic_ 14 

Determining whether the cipher alphabet is a standard, or a mixed cipher alphabet.. 15 

Determining whether the standard cipher alphabet is direct or revered...-... 16 


12. The four facts which can be determined from a study of the uniliteral frequency dis¬ 
tribution for a cryptogram, a. The following four facts (to be explained subsequently) can 
usually be determined from an inspection of the uniliteral frequency distribution for a given 
cipher message of average length, composed of letters: 

(1) Whether the cipher belongs to the substitution or the transposition class; 

(2) If to the former, whether it is monoalphabetic or polyalphabetic in character; 

(3) If monoalphabetic, whether the cipher alphabet is a standard cipher alphabet or a mixed 
cipher alphabet; 

(4) If standard, whether it is a direct or reversed standard cipher alphabet. 

6 . For immediate purposes the first two of the foregoing determinations are quite important 
and will be discussed in detail in the next two subparagraphs; the other two determinations will 
be touched upon very briefly, leaving their detailed discussion for subsequent sections of the 
text. 

13. Determining the class to which a cipher belongs.— a. The determination of the class 
to which a cipher belongs is usually a relatively easy matter because of the fundamental difference 
in the nature of transposition and of substitution as cryptographic processes. In a transposition 
cipher the original letters of the plain text have merely been rearranged, without any change 
whatsoever in their identities, that is, in the conventional values they have in the normal alpha¬ 
bet. Hence, the numbers of vowels (A, E, I, 0, U, Y), high-frequency consonants (D, N, R, S, T), 
medium-frequency consonants (B, C, F, G, H, L, M, P, V, W), and low-frequency consonants (J, K, 
Q, X, Z) are exactly the same in the cryptogram as they are in the plain-text message. Therefore, 
the percentages of vowels, high, medium, and low-frequency consonants are the same in the 
transposed text as in the equivalent plain text. In a substitution cipher, on the other hand, the 
identities of the original letters of the plain text have been changed, that is, the conventional 
values they have in the normal alphabet have been altered. Consequently, if a count is made 
of the various letters present in such a cryptogram, it will be found that the number of vowels, 
high, medium, and low-frequency consonants will usually be quite different in the cryptogram 
from what they are in the original plain-text message. Therefore, the percentages of vowels, 
high, medium, and low-frequency consonants are usually quite different in the substitution text 
from what they are in the equivalent plain text. From these considerations it follows that if in 
a specific cryptogram the percentages of vowels, high, medium, and low-frequency consonants 
are approximately the same as would be expected in normal plain text, the ciyptogram probably 
belongs to the transposition class; if these percentages are quite different from those to be 
expected in normal plain text the cryptogram probably belongs to the substitution class. 

(18) 


6 . In the preceding subparagraph the word “probably” Was emphasized by italicizing it, 
for there can be no certainty in every case of this determination. Uamlly these percentages in 
a transposition cipher are close to the normal percentages for plain text; usually, in a substitu¬ 
tion cipher, they are far different from the normal percentages for plain text. But occasionally 
a cipher message is encountered which is difficult to classify with a reasonable degree of certainty 
because the message is too short for the general principles of frequency to manifest themselves. 
It is clear that if in actual messages there were no variation whatever from the normal vowel 
and consonant percentages given in Table 3, the determination of the class to which a specific 
cryptogram belongs would be an extremely simple matter. But unfortunately there is always 
some variation or deviation from the normal. Intuition suggests that as messages decrease in 
length there may be a greater and greater departure from the normal proportions of vowels, 
high, medium, and low-frequency consonants, until in very short messages the normal propor¬ 
tions may not hold at all. Similarly, as messages increase in length there may be a lesser and 
lesser departure from the normal proportions, until in messages totalling a thousand or more 
letters there may be no difference at all between the actual and the theoretical proportions. 
But intuition is not enough, for in dealing with specific messages of the length of those commonly 
encountered in practical work the question sometimes arises as to exactly how much deviation 
(from the normal proportions) may be allowed for in a cryptogram which shows a considerable 
amount of deviation from the normal and which might still belong to the transposition rather 
than to the substitution class. 

c. Statistical studies have been made on this matter and some graphs have been constructed 
thereon. These are shown in Charts 1-4 in the form of simple curves, the use of which will now 
be explained. Each chart contains two curves marking the lower and upper limits, respectively, 
of the theoretical amount of deviation (from the normal percentages) of vowels or consonants 
which may be allowable in a cipher believed to belong to the transposition class. 

d. In Chart 1, curve Vi marks the lower limit of the theoretical amount of deviation from the 
normal number of vowels to be expected in a message of given length; curve V 2 marks the upper 
limit of the same thing. Thus, for example, in a message of 100 letters in plain English there 
should be between 33 and 47 vowels (A E I 0 U Y). Likewise, in Chart 2 curves Hi and 
mark the lower and upper limits as regards the high-frequency consonants. In a message of 100 
letters there should be between 28 and 42 high-frequency consonants (D N R S T). In Chart 3, 
curves Mi and Ms mark the lower and upper limits as regards the medium-frequency consonants. 
In a message of 100 letters there should be between 17 and 31 medium-frequency consonants 
(BCFGHLMPVW). Finally, in Chart 4, curves Li and La mark the lower and upper 
limits as regards the low-frequency consonants. In a message of 100 letters there should be 
between 0 and 3 low-frequency consonants (J K Q X Z). In using the charts, therefore, one 
finds the point of intersection of the vertical coordinate corresponding to the length of the 
message, with the horizontal coordinate corresponding to (1) the number of vowels, (2) the 
number of high-frequency consonants, (3) the number of mediimi-frequency consonants, and 
(4) the number of low-frequency consonants actually counted in the message. If all four points 
of intersection fall within the area delimited by the respective curves, then the number of vowels, 
high, medium, and low-frequency consonants corresponds with the number theoretically expected 
in a normal plain-text message of the same length; since the message under investigation is not 
plain text, it follows that the cryptogram may certainly be classified as a transposition cipher. 
On the other hand, if one or more of these points of intersection falls outside the area delimited 
by the respective curves, it follows that the cryptogram is probably a substitution cipher. The 
distance that the point of intersection falls outside the area delimited by these curves is a more or 
less rough measure of the improbability of the cry ptogram's being a transposition cipher. 












20 


e. Sometimes a cryptogram is encountered which is hard to classify with certainty even with 
the foregoing aids, because it has been consciously prepared with a view to making the classifica¬ 
tion difficult. This can be done either by selecting peculiar words (as in “trick cryptograms”) 
or by employing a cipher alphabet in which letters of approximately similar normal Jreqwncus 
have been interchanged. For example, E may be replaced by 0, T by R, and so on, thus yielding 



Number of letters in message. 

Ohabt No. 1._Curves marking the lower and upper limits of the theoretical amount of deviation from the normal number of vowels to be expected 

in messages of various lengths. (See Far. 13<f.) 


a cryptogram giving external indications of being a transposition cipher but which is really a 
substitution cipher. If the cryptogram is not too short, a close study will usually disclose what 
has been done, as well as the futility of so simple a subterfuge. 

y. In the majority of cases, in practical work, the determination of the class to which a 
cipher of average length belongs can be made from a mere iuspection of the message, after the 
cryptanalyst has acquired a familiarity with the normal appearance of transposition and of 
substitution ciphers. In the former case, his eyes very speedily note many high-frequency letters, 
such as E, T, N, R, 0, and S, with the absence of low-frequency letters, such as J, K, Q, X, 


21 


and Z; in the latter case, his eyes just as quickly note the presence of many low-frequency letters, 
and a corresponding absence of the usual high-frequency letters. 

g. Another rather quickly completed test, in the case of the simpler varieties of ciphers, is 
to look for repetitions oj groups of letters. As will become apparent very soon, recurrences of 
syllables, entire words and short phrases constitute a characteristic of all normal plain text. 
Since a transposition cipher involves a change in the sequence of the letters composing a plain- 



Number ot letters in message. 

Chabt No. 2.—Curves marking the lower and upper limits of the theoretical amount of deviation from the normal number of high-frequency oonso 
nants to be expected in messages of various iengths. (See Par. 13d.) 


text message,, such recurrences are broken up so that the cipher text no longer will show repetitions 
of more or less lengthy sequences of letters. But if a cipher message does show many repetitions 
and these are of several letters in length, say over four or five, the conclusion is at once warranted 
that the cryptogram is most probably a substitution and not a transposition cipher. However, 
for the beginner in cryptanalysis, it will be advisable to make the uniliteral frequency distribution, 
and note the frequencies of the vowels, the high, medimn, and low-frequency consonants. Then, 
referring to Charts 1 to 4, he should carefully note whether or not the observed frequencies for 





















consonants to be eipected In messages of various lengths. (See Par. IM.) 


of letters, figures and other symbols, it is immediately apparent that the cryptogram is a sub¬ 
stitution cipher. 

i. Finally, it should be mentioned that there are certain kinds of cryptograms whose class 
cannot be determined by the method set forth in subparagraphs b, c, d above. These exceptions 
will be discussed in a subsequent section of this text.* 

14. Determining whether a substitution cipher is monoalphabetic or polyalphabetic.— a. It 
will be remembered that a monoalphabetic substitution cipher is one in which a single cipher 
alphabet is employed throughout the whole message, that is, a given plain-text letter is invariably 
‘ Par. 47. 


represented throughout the message by one and the same letter in the cipher text. On the other 
hand, a polyalphabetic substitution cipher is one in which two or more cipher alphabets are 
employed within the same message; that is, a given plain-text letter may be represented by two or 
more different letters in the cipher text, according to some rule governing the selection of the 
equivalent to be used in each case. From this it follows that a single cipher letter may represent 
two or more different plain-text letters. 

h. It is easy to see why and how the appearance of the uniUteral frequency distribution for 
a substitution cipher may be used to determine whether the cryptogram is monoalphabetic or 
polyalphabetic in character. The normal distribution presents marked crests and troughs by 



Chabt No. 4.—Curves markiug the lower and upper limits of the theoretical amount of deviation from the normal number of low-frequency conso¬ 
nants to be expected in messages of various lengths. (See Par. 13if.) 

virtue of two circumstances. First, the elementary sounds which the symbols represent are 
used with greatly varying frequencies, it being one of the striking characteristics of every alpha¬ 
betic language that its elementary sounds are used with greatly varying frequencies.* In'the 
second place, except for orthographic aberrations peculiar to certain languages (conspicuously, 
English and French), each such sound is represented by the same symbol. It follows, therefore, 
that since in a monoalphabetic substitution cipher each different plain-text letter (=elementary- 
sound) is represented by one and only one cipher letter (=elementary symbol), the uniliteral 
frequency distribution for such a cipher message must also exhibit the irregular crest and trough 
appearance of the normal distribution, but with only this important modification —absolute 

> The student who is interested in this phase of the subject may find the following reference of value: Zipf' 
G. K., Selected Studies of the Principle of Relative Frequency in Language, Cambridge, Mass., 1932. 












































































24 


positions of the crests and troughs will not be the same as in the normal. That is, the letters accom¬ 
panying the crests and the troughs in the distribution for the cryptogram will be diflFerent from 
those accompanying the crests and the troughs in the normal distribution. But the marked 
irregularity of the distribution, the presence of accentuated crests and troughs, is in itself an 
indication that each symbol or cipher letter always represents the same plain-text letter in that 
cryptogram. Hence the general rule; A marked crest and trough appearance in the uniliteral 
frequency distribution jor a given cryptogram indicates that a single cipher alphabet is involved and 
constitvtes orie of the tests for a monoalphabetic substitution cipher. 

e. On the other hand, suppose that in a cryptogram each cipher letter represents several 
different plain-text letters. Some of them are of high frequency, others of low frequency. The 
net result of such a situation, so far as the uniliteral frequency distribution for the cryptogram 
is concerned, is to prevent the appearance of any marked crests and troughs and to tend to reduce 
the elements of the distribution to a more or less common level. This imparts a “flattened 
out” appearance to the distribution. For example, in a certain cryptogram of polyalphabetic 
construction, Ko=Ep, Gp, and Jp; Re=Ap, Dp, and Bp) Xc=0p, Lp, and Fp. The frequencies of 
Kp, Re, and Xo will be approximately equal because the summations of the frequencies of the several 
plain-text letters each of these cipher letters represents at different times will be about equal. 
If thin Bame phenomenon were true of all the letters of the cryptogram, it is clear that the 
frequencies of the 26 letters, when shown by means of the ordinary unUiteral frequency distribu¬ 
tion, would show no striking differences and the distribution would have the flat appearance of 
a typical polyalphabetic substitution cipher. Hence, the general rule: The absence of marked 
crests cmd troughs in the uniliieral freqaency distribution indicates that two or more cipher alphabets 
are involved. The flattened-out appearance of the distribution constitutes one of the tests for a poly¬ 
alphabetic substitution cipher. 

d. The foregoing test based upon the appearance of the frequency distribution constitutes 
only one of several means of determining whether a substitution cipher is monoalphabetic or 
polyalphabetic in composition. It can be employed in cases yielding frequency distributions 
from which definite conclusions can be drawn with more or less certainty by mere ocular exami¬ 
nation. In those cases in which the frequency distributions contain insufficient data to permit 
drawing definite conclusions by such examination, certain statistical tests can be appli^. These 
will be discussed in a subsequent text. 

e. At this point, however, one additional test will be given because of its simplicity of appli¬ 
cation. It may be employed in testing messages up to 200 letters in length, it being assumed that 
in messages of greater length ocular examination of the frequency distribution offers little or no 
difficulty. This test concerns the number of blanks in the frequency distribution, that is, the 
number of letters of the alphabet which are entirely absent from the message. It has been 
found from statistical studies that rather definite “laws” govern the theoretically expected num¬ 
ber of blanks in normal plain-text messages and in frequency distributions for cryptograms of 
different natures and of various sizes. The results of certain of these studies have been embodied 
in Chart 5. 

f. This chart contains two curves. The one labeled P applies to the average number of 
blnnka theoretically expected in frequency distributions baaed upon normal plain-text messages 
of the indicated lengths. The other curve, labeled R, applies to the average number of blanks 
theoretically expected in frequency distributions based upon perfectly random assortments of 
letters; that is, assortments such as would be found by random selection of letters out of a hat 
containing thousands of letters, all of the 26 letters of the alphabet being present in equal pro¬ 
portions, each letter being replaced after a record of its selection has been made. Such random 
assortments correspond to polyalphabetic cipher messages in which the number of cipher alpha¬ 


bets is so large that if iiniliteral frequency distributions are made of the letters, the distributions 
are practically identical with those which are obtained by random selections of letters out of a hat. 

g. In using this chart, one finds the point of intersection of the vertical coordinate corre¬ 
sponding to the length of the message, with the horizontal coordinate corresponding to the 
observed number of blanks in the distribution for the message. If tbia point of intersection falls 
closer to curve P than it does to curve B, the number of blanks in the message approximates or 
corresponds more closely to the number theoretically expected in a plain-text message than it 
does to a random (cipher-text) message of the same length; therefore, this is evidence that the 
cryptogram is monoalphabetic. Conversely, if this point of intersection falls closer to curve B 



Cbaet No. 6.—Corves showing the average number of blanks theoretically expected In distributions for plain text (P) and for random text (B) for 
messages of various lengths. (See Par. 14/-) 

than to curve P, the number of blanks in the message approximates or corresponds more closely 
to the number theoretically expected in a random text than it does to a plaiu-text message of the 
same length; therefore, this is evidence that the cryptogram is polyalphabetic. 

h. Practical examples of the use of this chart will be given in some of the illustrative messages 
to follow. 

16. Determining whether the cipher alphabet is a standard, or a mixed cipher alphabet.— 
a. Assuming that the uniliteral frequency distribution for a given cryptogram has been made, and 
that it shows clearly that the cryptogram is a substitution cipher and is monoalphabetic in 
character, a consideration of the nature of standard cipher alphabets ® almost makes it ob-vious 
how an inspection of the distribution will disclose whether the cipher alphabet involved is a 
standard cipher alphabet or a mixed cipher alphabet. If the crests and troughs of the distribu- 
* See Sec. VIII, Elementary Military Cryptography. 












26 

tion occupy positions which correspond to the rdaiive positions they occupy in the noW 
frequency distribution, then the cipher alphabet is a standard cipher alphabet If this is not the 
case, then it is highly probable that the cryptogram has been prepared by the use of a mixed 

cipher appUed in doubtful cases arising from lack of materia,! ava,ilable 

for study. Just what this test involves, and an illustration of its application will be given m the 

next section, using specific examples. , . . .. j 

16. Determing whether the standard cipher alphabet is direct or reversed.—Assuming 
that the frequency distribution for a given cryptogram shows clearly that a standard cipher 
alphabet is involved, the determination as to whether the alphabet is direct or reversed c^ also 
be made by inspection, since the difference between the two is merely a matter of the direchon 
in which the sequence of crests and troughs progresses—to the right, as m normal readmg or 
writing, or the left. In a direct cipher alphabet the direction in which the crests and troughs 
of the distribution should be read is the normal direction, from, left to right; in a reversed cipher 
alphabet this direction is reversed, from right to left. 


Section V 

UNttITERAL SUBSTITUTION WITH STANDARD CIPHER ALPHABETS 


Farsgrapb 

Principles of solution by construction and analysis of the unlliteral frequency distribution___ 17 

Theoretical example of solution..___________ 18 

Practical example of solution by the frequency method___ 19 

Solution by completing the plain-component sequence....... 20 

Special remarks on the method of solution by completing the plain-component sequence... 21 

Value of mechanical solution as a short cut________ 22 


17. Principles of solution by construction and analysis of the uniliteral frequency distri¬ 
bution.— a. Standard cipher alphabets are of two sorts, direct and reversed. The analysis of 
monoalphabetic cryptograms prepared by their use follows almost directly from a consideration of 
the nature of such alphabets. Since the cipher component of a standard cipher alphabet consists 
either of the normal sequence merely displaced 1, 2, 3, . . . intervals from the normal point of 
coincidence, or of the normal sequence proceeding in a reversed-normal direction, it is obvious 
that the uniliteral frequency distribution for a ciyptogram prepared by means of such a cipher 
alphabet emplbyed monoalphabetically will show crests and troughs whose relative positions 
and frequencies will be exactly the same as in the uniliteral frequency distribution for the plain 
text of that cryptogram. The only thing that has happened is that the whole set of crests and 
troughs of the distribution has been displaced to the right or left of the position it occupies in the 
distribution for the plain text; or else the successive elements of the whole set progress in the 
opposite direction. Hence, it follows that the correct determination of the plain-text value of the 
letter marking any crest or trough of the uniliteral frequency distribution will result at one 
stroke in the correct determination of the plain-text values of all the remaining 25 letters respec¬ 
tively marking the other crests and troughs in that distribution. Thus, having determined the 
value of a single element of the cipher component of the cipher alphabet, the values of all the 
remaining letters of the cipher component are automatically solved at one stroke. In more 
simple language, the correct determination of the value of a single letter of the cipher text 
automatically gives the values of the other 25 letters of the cipher text. The problem thus 
resolves itself into a matter of selecting that point of attack which will most quickly or most 
easily lead to the determination of the value of one cipher letter. The single word identification 
will hereafter be used for the phrase “determination of the value of a cipher letter”; to identify a 
cipher letter is to find its plain-text value. 

b. It is obvious that the easiest point of attack is to assume that the letter marking the crest 
of greatest frequency in the frequency distribution for the cryptogram represents Ep. Proceeding 
from this initial point, the identifications of the remaining cipher letters marking the other crests 
and troughs are tentatively made on the basis that the letters of the cipher component proceed 
in accordance with the normal alphabetic sequence, either direct or reversed. If the actual 
frequency of each letter marking a crest or a trough approximates to a fairly close degree the 
normal theoretical frequency of the assumed plain-text equivalent, then the initial identification 
0 o=Ep may be assumed to be correct and therefore the derived identifications of the other cipher 
letters may be assumed to be correct. If the original starting point for assignment of plain-text 
values is not correct, or if the direction of “reading” the successive crests and troughs of the 
(27) 










distribution is not correct, then the frequencies of the other 25 cipher letters will not correspond 
to or even approximate the normal theoretical frequencies of their hypothetical plain-text equiva¬ 
lents on the basis of the initial identification. A new initial point, that is, a different cipher 
equivalent must then be selected to represent Ep) or else the direction of “reading” the crests and 
troughs must be reversed. This procedure, that is, the attempt to make the actual frequency 
relations exhibited by uniliteral frequency distribution for a given cryptogram conform to the 
theoretical frequency relations of the normal frequency distribution in an effort to solve the 
cryptogram, is referred to technically as “fitting the actual uniliteral frequency distribution for a 
cryptogram to the thoretical uniliteral frequency distribution for normal plain text”, or, more 
briefly, as "Jitting the frequency distribution for the cryptogram to the normal frequency distribution", 
or, still more briefly, "fitting the distribution to the normal." In statistical work the expression 
commonly employed in connection with this process of fitting an actual distribution to a the¬ 
oretical one is “testing the goodness of fit.” The goodness of fit may be stated in various ways, 
mathematical in character. 

c. In fitting the actual distribution to the normal, it is necessary to regard the cipher com¬ 
ponent (that is, the letters A . . . Z marking the successive crests and troughs of the distribution) 
as partaking of the nature of a wheel or sequence closing in upon itself, so that no matter with 
what crest or trough one starts, the spatial and frequency relations of the crests and troughs are 
constant. This manner of regarding the cipher component as being cyclic in nature is valid 
because U is obvious that the relative positions and frequencies of the crests and troughs of anyunilitere^ 
frequency distribution must remain the same regardless of what letter is employed as the initial point 
of the distributim. Fig. 5 gives a clear picture of what is meant in this connection, as applied to 
the normal frequency distribution. 


g g g ggg=:g g I 

g^5g ==gg ggg g-,3g 

g^gggg^gg ggggg ggggss^g g^gggg 

ABCDEFGHIJKLMNOPQRSTUVWXYZABCDEP. 


g 5 g 
gggg^g 

.FEDCBAZYX 


g = g gg g ? 2 

ggg gg^ g-. gS-g 

= 5gggg ggggg gg5gggg==g 

fVUTSRQPONMLKJIHGFEDCBA 


d. In the third sentence of subparagraph b, the phrase “assumed to be correct” was ad¬ 
visedly employed in describing the results of the attempt to fit the distribution to the normal, 
because the final test of the goodness of fit in this connection (that is, of the correctness of the 
assignment of values to the crests and troughs of the distribution) is whether the consistent 
substitution of the plain-text values of the cipher characters in the cryptogram will ^eld intelli¬ 
gible plain text. If this is not the case, then no matter how close the approximation between 
actual and theoretical frequencies is, no matter how well the actual frequency distribution fits 
the normal, the only possible inferences are that (1) either the closeness of the fit is a pure coin¬ 
cidence in this case, and that another equally good fit may be obtained from the same data, or 
else (2) the cryptogram involves sometUng more than simple monoalphabetic substitution by 


29 


means of a single standard cipher alphabet. For example, suppose a transposition has been 
applied in addition to the substitution. Then, although an excellent correspondence between 
the imiliteral frequency distribution and the normal frequency distribution has been obtained, 
the substitution of the cipher letters by their assumed equivalents will still not yield plain text. 
However, aside from such cases of double encipherment, instances in which the uniliteral fre¬ 
quency distribution may be easily fitted to the normal frequency distribution and in which at 
the same time an attempted simple substitution fails to yield intelligible text are rare. It may be 
said that, in practical operations whenever the uniliterd frequency distribution can be made to 
fit the normal frequency distribution, substitution of values will result in solution; and, as a 
corollary, whenever the uniliteral frequency distribution cannot be made to fit the normal 
frequency distribution, the cryptogram does not represent a case of simple, monoalphabetic 
substitution by means of a standard alphabet. 

18. Theoretical example of solution.— a. The foregoing principles will become clearer by 
noting the cryptographing and solution of a theoretical example. The following message is to be 
cryptographed. 

HOSTILE FORCE ESTIMATED AT ONE REGIMENT INFANTRY AND TWO PLATOONS CAVALRY 
MOVING SOUTH ON QUINNIMONT PIKE STOP HEAD OF COLUMN NEARING ROAD JUNCTION SEVEN 
THREE SEVEN COMMA EAST OF GREENACRE SCHOOL FIRED UPON BY OUR PATROLS STOP 
HAVE DESTROYED BRIDGE OVER INDIAN CREEK . 

b. First, solely for purposes of demonstrating certain principles, the uniliteral frequency dis¬ 
tribution for this message is presented in Figure 6. 


.. g g g = 

g g § gg g^g 

g 5tg -,g ^^gg^ ggg..^ 

g=:ggggggg-- = ggggg^ggggg- g 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 


c. Now let the foregoing message be cryptographed monoalphabetically by the following 
cipher alphabet, yielding the cryptogram and the frequency distribution showm below. 


Plain— 

.. A 

BCD 

E F G H 

I J K 

L M N 0 

P Q R 

S T U V 

W X Y 

Z 

Cipher.. 

_ G 

H I J 

K L M N 

0 P Q 

R S T U 

V W X 

Y Z A B 

C D E 

F 

Plain..... 

...HOSTI 

LEFOR 

CEEST 

IMATE 

DATON 

EREGI 

MENTI 

NFANT 

RYAND 

Cipher_ 

...NUYZO 

RKLUX 

IKKYZ 

OSGZK 

JGZUT 

KXKMO 

SKTZO 

TLGTZ 

XEGTJ 

Plain... 

..TWOPL 

ATOON 

SCAVA 

LRYMO 

VINGS 

OUTHO 

NQUIN 

NIMON 

TPIKE 

Cipher.. 

..ZCUVR 

GZUUT 

YIGBG 

RXESU 

BOTMY 

UAZNU 

TWAOT 

TOSUT 

ZVOQK 

Plain. 

..STOPH 

EADOF 

COLUM 

NNEAR 

INGRO 

ADJUN 

CTION 

SEVEN 

THREE 

Cipher.. 

..YZUVN 

KGJUL 

lURAS 

TTKGX 

OTMXU 

GJPAT 

IZOUT 

YKBKT 

ZNXKK 

Plain. 

..SEVEN 

COMMA 

EASTO 

FGREE 

NACRE 

SCHOO 

LFIRE 

DUPON 

BYOUR 

Cipher.. 

..YKBKT 

lUSSG 

KGYZU 

LMXKK 

TGIXK 

YINUU 

RLOXK 

JAVUT 

HEUAX 

Plain.. 

..PATRO 

LSSTO 

PHAVE 

DESTR 

OYEDB 

RIDGE 

OVERI 

NDIAN 

CREEK 

Cipher. 

...VGZXU 

RYYZU 

VNGBK 

JKYZX 

UEKJH 

XOJMK 

UBKXO 

TJOGT 

IXKKQ 
















30 


Crtptogbam 

NUYZO RKLUX IKKYZ OSGZK JGZUT KXKMO 
SKTZO TLGTZ XEGTJ ZCUVR GZUUT YIGBG 
RXEsS loTMY UAZNU TWAOT TOSUT ZVOQK 
YZUVN KGJUL lURAS TTKGX OTMXU GJPAT 
IZOUT YKBKT ZNXKK YKBKT lUSSG KGYZU 
LMXKK TGIXK YINUU RLOXK JAVUT HEUAX 
VGZXU RYYZU VNGBK JKYZX UEKJH XOJMK 
UBKXO TJOGT IXKKQ 


g i ^ § 

a g g ggg=:g 

g $5g ggg 

ii 1 = 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

d Let the student now compare Figs. 6 and 7, which have been superposed in Fig. 8 
for convwiienee in examinAtion. Crests and troi^hs are present m both ^tnbutir I 
their relative positions and frequencies have not been changed m the partied, ^ly 

the absolute position of the sequence as a whole has been displaced six mtervals to the right m 
Fig 7, as compared with the absolute position of the sequence m Fig. 6. 



i g 5 gg g = g 

g =:5g ^ = ggg..-, 

I g g g g g g g - = g g ^ ^ ^ ^ ^ ^ ^ ^ ^ 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 


g = g 

S g g g ^ 

I g g § ggg:=g 

I g sig ^g -- = gg-^ ggl 

ii 5 g:sggggggg- = ggggg~-^^^ 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Tiamt 8. 

e If the two distributions are compared in detail the student will clearly imderstand how 
easy the solution of the cryptogram would be to one who knew nothing about how it was prepay. 
For example, the frequency of the highest crest, representing Ep m Fig. 6 « p 

four letters before Ep there is another crest representmg Ap with frequency 16. Between A and E 
there is a trough, representing the low-frequency letters B, C, D. On the other side of E, at an 
interval of four letters, comes another crest, representmg I with frequency U. Between E and I 
there is another trough, representing the low-frequency lettere F 

and troughs with their homologous crests and troughs m Fig. 7. In the latter, the letter K 
marks the highest crest in the distribution with a frequency of 28; fom letters before K there is 
another crest, frequency 16, and four letters on the other side of K there is another crest, frequency 


31 


14. Troughs corresponding to B, C, D and F, G, H are seen at H, I, J and L, M, N in Fig. 7. In 
fact, the two distributions may be made to coincide exactly, by shifting the frequency distribution 
for the cryptogram six intervals to the left with respeet to the distribution for the equivalent 
plain-text message, as shown herewith, 

2 g g 

S ^ g g g ^ 

ig g § gg g^g 

bg 5ig -.g ^ g g .. g g g „ 

g 55 g g g g g gg ^ g g g g g .. g g g g g ^ 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

i 55 g 

i ^ g g g 5: 

Ig g § gg g55g 

Sg 5§g ^g ^ 5: g g .. g g g 

g = g g g g g g g g g g g g ^ g g g g g -- 5 

GHIJKLMNOPQRSTUVWXYZABCDEF 

/. Let us suppose now that nothing is known about the cryptographing process, and that 
only the ciyptogram and its uniliteral frequency distribution is at hand. It is clear that simply 
bearing in mind the spatial relations of the crests and troughs in a normal frequency distribution 
would enable the cryptanalyst to fit the distribution to the nonpal in this case. He would 
naturally first assume that Ge=Ap, from which it would follow that if a direct standard alphabet 
is involved, Ho=Bp, Io=Cp, and so on, yielding the following (tentative) deciphering alphabet: 

apher. _ ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Plain _ UVWXYZABCDEFGHIJKLMNOPQRST 

g. Now comes the final test: If these assumed values are substituted in the cipher text, 
the plain text immediately appears. Thus: 

NUYZO RKLUX IKKYZ OSGZK JGZUT etc. 

HOSTI LEFOR CEEST IMATE DATON etc. 

h. It should be clear, therefore, that the selection of Gc to represent Ap in the cr 3 rptc^raphii^ 
process has absolutely no effect upon the relative spatial and frequency relations of the crests 
and troughs of the frequency distribution for the cryptogram, If Qc had been selected to repre¬ 
sent Ap, these relations would still remain the same, the whole series of crests and troughs being 
merely displaced further to the right of the positions they occupy when Ge=Ap. 

19. Practical example of solution by the frequency method.— a. The case of direct standard 
alphabet ciphers. —(1) The following cryptogram is to be solved by applying the foregoing 
principles: 

IBMQO PBIUO MBBG A JCZO F MUUQB A J C Z 0 
ZWILN QTTML EQBPU IZKPQ VOQVN IVBZG 

(2) From the presence of repetitions and sd many low-frequency letters such as B, Q, and 
Z it is at once suspected that this is a substitution cipher. But to illustrate the steps that must 
be taken in difficult cases in order to be certain in this respect, a uniliteral frequency distribution 







35 


34 

he win note that the relative positions and extensions of the crests and troughs are identical; 
they merely progress in opposite directions. 

20. Solution hy completing the plain-component sequence.— a. The case oj direct standard 
alphabet ciphers. —(1) The foregoing method of analysis, involving as it does the construction of ^ 

a uniliteral frequency distribution, was termed a solution by the frequency method because it in- 
volves the construction of a frequency distribution and its study. There is, however, another f 

method which is much more rapid, almost wholly mechanical, and which, moreover, does not 
necessitate the construction or study of any frequency distribution whatever. An understand¬ 
ing of the method follows from a consideration of the method of enciphferment of a message 
by the use of a single, direct standard cipher alphabet. 

(2) Note the following encipherment: 

Message.. REPEL INVADING CAVAIJ^Y 

Enciphering Alphabet 

Pldn_ ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher. GHIJKLMNOPQRSTUVWXYZABCDEF 

Encipherment 

Plain text_- REPEL INVADING CAVALRY 

Cryptogram.... XKVKR OTBGJOTM IGBGRXE 

Cryptogram 

XKVKR OTBGJ 0TMIG BGRXE 

(3) The enciphering alphabet shown above represents a case wherein the sequence of letters 
of both components of the cipher alphabet is the normal sequence, with the sequence forming the 
cipher component merely shifted six intervals in retard (or 20 intervals in advance) of the posi¬ 
tion it occupies in the normal alphabet. If, therefore, two strips of paper bearing the letters of 
the normal sequence, equally spaced, are regarded as the two components of the cipher alphabet 
and are juxtaposed at aU of the 25 possible points of coincidence, it is obvious that one of these 
25 juxtapOsitiofts mast correspond to the actual juxtaposition shown in the encipherii^ alphabet 
directly above.* It is equally obvious that if a record were kept of the results obtained by ap¬ 
plying the values-given at each juxtaposition to the letters of the cryptogram, one of these results 
would yield the plain text of the cryptogram. 

(4) Let the work be systematized and the results set down in ah orderly manner for exam¬ 
ination. It is obviously unnecessary to juxtapose the two components so that Ae=Ap, for on 
the assumption of a direct standard alphabet, juxtaposing two direct normal components at 
their normal point of coincidence merely yields plain text. The next possible juxtaposition, 
therefore, is Ao=Bp. Let the juxtaposition of the two sliding strips therefore be Ac=Bp, as shown 


here: 

Plain. ABCDEFGHIJKLMNOPQRSTUVWXYZABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher. ABCDEFGHIJKLMNOPQRSTUVWXYZ 

The values given by this juxtaposition are substituted for the first 20 letters of the cryptogram 
and the following results are obtained. 

Cryptogram. XKVKR OTBGJ OTMIG BGRXE 


1st TesW'Plain text”_ YLWLS PUCHK PUNJH CHSYF 


* One of the strips should bear the sequence repeated. This permits juxtaposing the two sequences at all 26 
possible points of coincidence so ag to hiiv^ a complete cipher alphabet showing at all times. 


This certainly is not intelligible text; obviously, the two components were not in the position 
indicated in this first test. The cipher component is therefore slid one interval to the right, 
making A,=Cp, and a second test is made. Thus 


Plain- ABCDEFGHIJKLMNOPQRSTUVWXYZABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher.- ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cryptogram.. XKVKR OTBGJ OTMIG BGRXE 


2d Tesi^'Tlain text”. ZMXMT QVDIL QVOKI DITZG 

Neither does the second test result in disclosing any plain text. But, if the results of the two 
tests are studied a phenomenon that at first seems quite puzzling comes to hgbt. Thus, suppose 
the results of the two tests are superimposed in this fashion. 

Cryptogram. XKVKR OTBGJ OTMlG BGRXE - 

1 st Test—“Plain text”_ YLWLS P U C H K PUNJH CHSYF 

2nd Test—“Plain text”... ZMXMT QVDIL QVOKI DITZG 

(5) Note what has happened. The net result of the two experiments was merely to continue 
the normal sequence begun by the cipher letters at the heads of the several columns. It is 
obvious that if the normal sequence is completed in each column the results will be exactly the same 
as though the whole set of 85 possible tests had actually been performed. Let the columns therefore 
be completed, as shown in Fig. 11. 

XKVKROTBQJOTMIGBGRXE 
YLWLSPUCHKPUNJHCHSYF 
ZMXMTQVDILQVOKIDITZG 
ANYNURWEJMRWPLJEJUAH 
BOZOVSXFKNSXQMKFKVBI 
CPAPWTYGLOTYRNLGLWCJ 
DQBQXUZHMPUZSOMHMXDK 
ERCRYVAINQVATPNINYEL 
F S D S Z W B J 0 R W B U Q 0 J 0 Z F M 
GTETAXCKPSXCVRPKPAGN 
HUFUBYDLQTYDWSQLQBHO 
IVGVCZEMRUZEXTRMRCIP 
JWHWDAFNSVAFYUSNSDJQ 
KXIXEBGOTWBGZVTOTEKR 
LYJYFCHPUXCHAWUPUFLS 
MZKZGDIQVYDIBXVQVGMT 
N A L A H E J R W Z E J C Y W R W H N U 
OBMBIFKSXAFKDZXSXIOV 
PCNCJGLTYBGLEAYTYJPW 
QDODKHMUZCHMFBZUZKQX 
♦REPELINVADINGCAVALRY 
SFQFMJOWBEJOHDBWBMSZ 
TGRGNKPXCFKPIECXCNTA 
UHSHOLQYDGLQJFDYDOUB 
VITIPMRZEHMRKGEZEPVC 
WJUJQNSAF'INSLHFAFQWD 

FlOUBl 11. 

An examination of the successive horizontal lines of the diagram discloses one and only one line 
of plain text, that marked by the asterisk and reading REPELINVADINGCAVALRY. 


















(6) Since each column in Fig. 11 is nothing but a normal sequence, it is obvious that instead 
of laborioudy writing down these columns of letters every time a crjqjtogram is to be examined, 
it would be more convenient to prepare a set of strips each bearing the normal sequence doubled 
(to permit complete coincidence for an entire alphabet at any setting), and have them available 
for examining any future cryptograms. In using such a set of sliding strips in order to solve a 
cryptogram prepared by means of a single direct standard cipher alphabet, or to make a test to 
determine whether a cryptogram has been so prepared, it is ody necessary to “set up” the letters 
of the cryptogram on the strips, that is, align them in a single row across the strips (by sliding 
the individual strips up or down). The successive horizontal lines, called generatrices (singular, 
generatrix), are then examined in a search for intelligible text. If the cryptogram really belongs 
to this simple type cipher, one of the generatrices vdll exhibit intelligible text all the way 
across; this text will practically invariably be the plain text of the message. This method of 
analysis may be termed a solviion by competing the flainrcomponent sequence. Sometimes it is 
referred to as “running down” the sequence. The principle upon which the method is based 
constitutes one of the cryptanalyst’s most valuable tools.^ 

b. ea^ qf reverb standard <dphahets.-^{l) The method described under subpar. a may 
be,applied; in slightly modihed form, in the case of a cryptogram enciphered by a single 
reversed standard alphabet. The baric principles are identical in the two cases. 

(2) To show this it is necessary;to esperimont with two sliding components as before, except 
that in this case one of the components must be n reversed normal sequence, the other, a direct 
normal sequence. 

(3) Let the two components be juxtaposed A to A, as shown below, and then let the resultant 
Values be substituted for the letters of the cryptogram. Thus: 


PCRCV YTLGD YTAEG LG VP I 

_ ABCDEFGHIJKLMNOPQBSTUVWXYZABCDEFGHUKLMNOPQRSTUVWXYZ 

-. ZYXWVUTSRQPONMLKJIHGFEDCBA 


Cryptogram___ ,P C R C V 

Ist Test—“Plain text”— L Y J Y F 


:y T A E G 
C H A W U 


L G V P I 
P U F L S 


(4) This does not yields intelligible text, a.nd therefore the reversed component is slid one 
space forward and a second test is made. Thus: 

Plain_ ABCDEFGHIJKLMNOPQRSTUVWXYZABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher...... ZYXVmJTSRQPONMLKJIHGFEDCBA 


Cryptogram-.... P C R C V 

2d Test-“Plain text”.... M Z K Z G 


Y T L G D 
D I Q V Y 


YTAEG 
D I B X V 


L G V P I 
Q V G M T 


(5) Neither does the second test 3deld intelligible text. But let the results of the two tests 
be superimposed. Thus: 

Cryptogram. PCRCV Y.TLGD YTAEG LGVPI 

Ist Test—“Plain text”... LYJYF CHPUX CHAWU PUFLS 

2d Tesl^“Plain text”_ MZKZG DIQVY DIBXV QVGMT 

• It is recommended that the student prepare a set of 25 strips by H by 15 inches, made of well-seasoned 
wood, and glue alphabet strips to the wood. The alphabet on each strip should be a double or repeated alphabet 
with all letters equally si>aoed. 


37 


1 (6) It is seen that the letters ctf the ^‘{dain text” given by the second trial are merrily the 
continuants of the normal sequences initiated by the letters of the “plain text” given by the first 
trial. If these sequencee are “run down”—that is, completed within the columnn—the results 
must obviously be the same as though successive tests exactly Mmilnr to the first two were 
applied to the cryptogram, using one reversed normal and one direct normal component. If the 
cryptogram has really been prepared by means of a single reversed standard alphabet, one of 
the generatrices of the diagram that r^ults from completing the sequences must yield intelligible 
text. 

(7) Let the diagram be made, or better yet, if the student has alrealdy at hand the set of 
sliding strips referred to m the footnote to page 36, let him “set up” the letters given by the 
first trial. jRg. 12 shows the diagram and indicates the plain-text generatrix. 

PCRCVYTLGDYTAEGLGVPI 
L Y J Y F C H P U X C H A W U P U F L S 
MZKZGDIQVYDIBXV QVGMT 
NALAHEJRWZEJCY W R W H N U 
OBMBIFKSXAFKDZXSXIOV 
PCNCJGLTYBGLEAYTYJPW 
Q D 0 D K H M U Z C H M F B Z U Z K Q X 
*REPELINVADINGCAVALRY 
S F Q F M J 0 W B E J 0 H D B W B M S Z 
T G R G N K P X C F K P I E C X C N T A 
UHSHOLQYDGLQJFDYDOUB 
VITIPMRZEHMRKGEZEPVC 
WJUJQNSAFINSLHFAFQWD 
XKVKROTBGJOTMIGBGRXE 
YLWLSPUCHKPUNJHCHSYF 
Z M X M T Q V D I L Q V 0 K I D I T Z G 
/ ANYNURWEJMRWPLJEJUAH 

/ BOZOVSXFKNSXQMKFKVBI 

/ C P A P W T Y G L 0 T Y R N L G L W C J 

DQBQXUZHMPUZSOMHMXDK 
ERCRYVAINQVATPNINYEL 
FSDSZWBJORWBUQOJOZFM 
GTETAXCKPSXCVRPKPAGN 
HUFUBYDLQTYDWSQLQBHO 
IVGVCZEMRUZEXTRMRCIP 
JWHWDAFNSVAFYUSNSDJQ 
KXIXEBGOTWBGZVTOTEKR 

(8) The only difference in procedure between this case and the preceding one (where the 
cipher alphabet was a direct standard alphabet) is that the letters of the cipher text are first 
“deciphered” by means of amy reversed standard alphabet and then the columns are “run down”, 
according to the normal A B C . . . Z sequence. For reasons which will become apparent very 
soon, the first step in this method is techmcally termed converting the cipher letters into their 
plainrcomponent equivalents; the second step is the same as before, viz, completing the plain-com¬ 
ponent sequence. 











38 


21. Special remarks on tke method of solution by completing the plamroomponent sequence.— 
a. The terms employed to designate the steps in the solution set forth in Par. 206, viz, “con¬ 
verting the cipher letters into their plain-component equivalents” and “completii^ the plain- 
component sequence”, accurately describe the process. Their meaning will become more clear 
as the student j^ogresses with the work. It may be said that whenever the plsdn component of 
a cipher alphabet is a known sequence, no matter how it is composed, the difficulty and time 
required to s<rfve any cryptogram involving the use of that plain component is practically out 
in half. In some cases this knowledge facilitates, and in other cases is the only thing that makes 
possible the solution of a very short cryptogram that might otherwise defy solution, lAter on an 
example will be given to illustrate what is meant in this regard. 

6 . The student should take note, however, of two qualifying expressions that were employed 
in a preceding paragraph to describe the results of the application of the method. It was stated 
that “one of the generatrices will exhibit intelligible text all the way across; this text will practically 
invariably be the plain text.” 'Will there ever be a case in which more than one generatrix will 
yield intelligible text throi^hout its extent? That obviously depends almost entirely on the 
number of letters that are aligned to form a generatrix. If a generatrix contains but a very few 
letters, only five, for example, it may happen as a result of pure chance that there will be two or 
more generatrices shoving what m^ht be “intelligible text.” Note in 11, for example, that 
there are several cases m^^ffich 3*letter and 4-letter English words (ANYj VAIN, GOT, TIP, etc.) 
appear on generatrices that {Uenot correct, these words being formed by pure chance. But there 
is not a single case, in th& diagram, of a-6-letter or longer word apfieming fortuitously, because 
obviously the longer ttie word the smaller the probabili^ of its appearance purely by chance; 
and the probability that two generatrices of 15 letters each will both yield intelligible text along 
their entire length is exceedingly remote, so remdte, in fact, that in practical cryptography such 
a case may be considered nonexistent.* 

c. The student should observe that in reality there is no difference whatsoever in principle 
between the two methods presented in subpars. a and b of Par. 20. In the former the preliminary 
step of converting the cipher letters ihto their plain-component equivalents is apparently not 
present but in reality it is there. The reason for its apparent absence is that in that case the 
plain component of the cipher alphabet is identical in all respects with the cipher component, so 
that the cipher letters require no conversion, or, rather, they are identical with the equivalents 
that would result if they Were converted on the basis Ac=Ap. In fact, if the solution process had 
been arbitrarily initiated by converting the cipher letters into their plain-component equivalents 
at the setting A,=0p, for example, and the cipher component slid one interval to the right there¬ 
after, the results of the first and second tests of Par. 20a would be as follows: 

Cryptogram___ XKVKROTBGJOTMIGBGRXE 

1st Test—“Plain text”_ LYJYFCHPUXCHAWUPUFLS 

2nd Tes(^“Plain text”_ MZKZGDIQVYDIBXVQVGMT 

Thus, the foregoing diagram duplicates m every particular the diagram resulting from the first 
two tests under Par. 206: a first line of cipher letters, a second line of letters derived from them 
but showing externally no relationship with the first line, and a third line derived immediately 
from the second line by continuing the direct normal sequence. This point is brought to attention 
only for the purpose of showing that a single, broad principle is the basis of the general metbod of 
solution by completing the plain-component sequence, and once the student has this firmly in 

^ A person with patience and an inclination toward the curiosities of the science might construct a text of 15 
or more letters which would yield two “intelligible” texts on the plain-component completion diagram. 


mind he will have no difficulty whatsoever in realizing when the principle is applicable, what a 
powerful cryptanalytic tool it can be, and what results he may expect from its application in 
specific instances. 

d. In the two foregoing examples of the application of the principle, the plain component 
was a normal sequence but it should be clear to the student, if he has grasped what has been said 
m the preceding subparagraph, that this component may be a mixed sequence which, if known 
(that is, if the sequence of letters comprising the sequence is known to the cryptanalyst), can be 
handled just as readily as can a plain component that is a normal sequence. 

^ e. It is entirely unmaterial at what points the plain and the ciphqr components are juxtaposed 
m the preliminary step of converting the cipher letters into their plain-component equivalents. 
For example, in the case of the reversed alphabet cipher solved in Par. 206, the two components 
were arbitrarily juxtaposed to give the value A=A, but they might have been juxtaposed at any 
of the other 25 possible points of coincidence without in any way affecting the final result, viz, the 
production of one plain-text generatrix in the completion diagram. 

22. Value of mechanical solution as a short cut.—o. It is obvious that the very first step 
the student should take in his attempts to solve an unknown cryptogram that is obviously a 
substitution cipher is to try the mechanical method of solution by completing the plain-component 
sequence, using the normal alphabet, first direct, then reversed. This takes only a very few 
nmutes and is conclusive in its results. It saves the labor and trouble of constructing a frequency 
ffistribution in case the cipher is of this simple type. Later on it will be seen how certain varia¬ 
tions of this simple type may also be solved by the application of this method. Thus, a vwy 
easy short cut to solution is afforded, which even the experienced cryptanalyst never overlooks 
in his first attack on an unknown cipher. 

6 . It is important now to note that if neither of the two foregoing attempts is successful in 
bringing plain text to light and the cryptogram is quite obviously monoalphabetic in character, the 
cryptanalyst is warranted in assuming that the cryptogram involves a mixed cipher alphalet^ The 
steps to be taken in attacking a cipher of the latter type will be discussed in the next section. 

« There is but one other possibility, already referred to under Par. 17d, which involves the case where trans¬ 
position and monoalphabetic substitution processes have been applied in successive steps. This is unusual 
however, and will be discussed in its proper place. * 







UNILITEEAL SUBSTITUTION WITH MIXED CIPHER ALPHABETS 

Ftiagnpli 

Basic reasoa for the low degree of cryptographic security afforded by monoalphabetic cryptograms involving 

standard cipher alphabets--- 23 

Preliminary steps in the analysis of a monoalphabetic, mixed-alphabet cryptogram- 24 

Further data concerning normal plain text- 26 

Preparation of the work sheet- 26 

Triliteral-frequency distributions------ "7 

Classifying the cipher letters into vowels and consonants.— 28 

Further analysis of the letters representing vowels and consonants...— 29 

Substituting deduced values in the cryptogram.. 30 

Completing the solution..—.. 

The “probable-word” method; its value and applicabiUty—.... 33 

Solution of additional cryptograms produced by the same cipher component..- 34 

23. Btisdc reason for the low degree of cryptographic security afforded by monoalphabetic 
cryptogranm involying standard cipher alphabets.—The student has seen that the solution of 
monoalphabetic cryptograms involving standard cipher alphabets is a very easy matter, T^o 
methods of analysis were described, one involving the construction of a frequency distribution, 
the other not requiring this kind of tabulation, being almost mechanictd in nature and eoi^ 
spondingly rapid. In the first of these two methods it was necessary to make a correct assumption 
as to theyalue of but one of the 26 letters of the cipher alphabet and the values of the remaining 
25 letters at once become known; in the second method it was not necessary to assume a value 
for even a single cipher letter. The student should understand what constitutes the basis of Ibis 
situation, viz, the fact that the two components of the cipher alphabet are composed of known 
sequences. Wiat if one or both of these components are, for the cryptanalyst, unknown sequences^ 
In other words, what difficulties will confront the cryptanalyst if the cipher component of the 
cipher alphabet is a mixed sequence? Will such an alphabet be solvable as a whole at one stroke, 
or will it be necessary to solve its values individually? Since the determination of the value of 
one cipher letter in this case gives no direct clues to the value of any other letter, it would seem 
that the solution of such a cipher should involve considerably more analysis and experiment than 
has the solution of either of the two types of ciphers so far examined occasioned. A typical 
example will be studied. 

24. Preliminary steps in the analysis of a monoalphabetic, mixed alphabet cryptogram.— 
a. Note the following cryptogram: 

SFDZF lOGHL PZFGZ DYSPF HBZDS GVHTF UPLVD FGYVJ VFVHT GADZZ AITYD 

ZYFZJ ZTGPT VTZ BD VFHTZ DFX SB GIDZY VTXOI YVTEF VMGZZ THLLV XZDF M 

HTZAI TYDZY BDVFH TZDFK ZDZZJ SXISG ZYGAV FSLGZ DTHHT CDZRS VTYZD 

QZFF H TZAIT YDZYG AVDGZ ZTK HI TY ZYS DZGHU ZFZTG UPGDI XWGHX ASRUZ 

DFUID EGHTV EAGXX 

b. A casual inspection of the text discloses the presence of several long repetitions as well as 
of many letters of normally low frequency, such as F, G, V, X, and Z; on the other hand, letters of 


41 


normally high frequency, such as the vowels, and the consonants N and R, are relatively scarce. 
The cryptogram is obviously a substitution cipher and the usual mechanical tests for determining 
whether it is possibly of the monoalphabetic, standard-alphabet type are applied. The results 
being negative, a uniliteral frequency distribution is immediately constructed and is as shown 
in Figure 13. 

g 

g 

5 g 

g g g g .. g 

gggg g g gg 

^ ggggg ggg^gg 

g g .. g $ g g g g 5 g == Sg g g g 1 ^ g g g 
ABCDEFGHIJKLMNOPQRSTUVWXYZ 

8 4 1233 19 I9 1S 10 3 2 5 3 0 3 5 0 2 10 338 18 18 14 33 

Fioxmx IS 

c. The fact that the frequency distribution shows very marked crests and troughs means 
that the cryptogram is imdoubtedly monoalphabetic; the fact that it has already been tested 
(by the method of completing the plain-component sequence) and found not to be of the mono- 
alphabetic, standard-alphabet type, indicates with a high degree of probability that it involves 
a mixed cipher alphabet. A few moments might be devoted to making a careful inspection of the 
distribution to insure that it cannot be made to fit the normal; the object of this would be to 
rule out the possibility that the text resulting from substitution by a standard cipher alphabet 
had not subsequently been transposed. But this inspection in this case is hardly necessary, in 
view of the presence of long repetitions in the message.* (See Par. 13p.) 

d. One might, of course, attempt to solve the cryptogram by applying the simple principles 
of frequency. One might, in other words, assume that Zg (the letter of greatest frequency) 
represents Ep, D, (the letter of next greatest frequency) represents Tp, and so on. If the message 
were long enough this simple procedure might more or less quickly give the solution. But the 
message is relatively short and many difficulties would be encountered. Much time and effort 
would be expended unnecessarily, because it is hardly to be expected that in a message of only 
235 letters the relative order of frequency of the various cipher letters should exactly coincide 
with, or even closely approximate the relative order of frequency of letters of normal plain text 
found in a count of 50,000 letters. li is to be emphasized that the beginner must repress the natural 
tendency to place too much confdence in the generalized principles of frequency and to rely too much 
upon them. It is far better to bring into effective use certain other data concerning normal 
plain text which thus far have not been brought to notice. 

25. Further data concerning normal plain text,— a. Just as the individual letters constituting 
a large volume of plain text have more or less characteristic or fixed frequencies, so it is found 
that digraphs and trigraphs have characteristic frequencies, when a large volume of text is 
studied statistically. In Appendix 1, Table 6, are shown the relative frequencies of all digraphs 
appearing in the 260 telegrams referred to in Paragraph 9e. It will be noted that 428 of the 676 
possible pairs of letters occur in these telegrams, but whereas many of them occur but once or 
twice, there are a few which occur hundreds of times. 

b. In Appendix 1 will also be found several other kinds of tables and lists which will be useful 
to the student in his work, such as the relative order of frequency of the'50 digraphs of greatest 

• This possible step is mentioned here for the purpose of making it clear that the plain-component sequence 
completion method cannot solve a case in which transposition has followed or preceded monoalphabetic substi¬ 
tution with standard alphabets. Cases of this kind will be discussed in a later text. It is sutScient to indicate 
at this point that the frequency distribution for such a combined substitution-transposition cipher would present 
the characteristics of a standard alphabet cipher—and yet the method of completing the plain-component 
sequence would fail to bring out any plain text. 
















42 


frequency, the relative order of frequency of doubled letters, doubled vowels, doubled consonants, 
and so on. It is suggested that the student refer to this appendix now, to gain an idea of the 
data available for his future reference. Just how these data may be employed will become ap¬ 
parent very shortly. 

26. Preparation of the work sheet.—o. The details to be considered in this paragraph may 
at first appear to be superfluous but long experience has proved that systematization of the 
work, and preparation of the data in the most utilizable, condensed form is most advisable, even 
if this seems to take considerable time. In the first place if it merely serves to avoid interrup¬ 
tions and irritations occasioned by failure to have the data in an instantly available form, it 
will pay by saving mental wear and tear. In the second place, especially in the case of com¬ 
plicated cryptograms, painstaking care in these details, while it may not always bring about 
success, is often the factor that is of greatest assistance in ultimate solution. The detailed 
preparation of the data may be irksome to the student, and he may be tempted to avoid as much 
i of it as possible, but, unfortunately, in the early stages of solving a cryptogram he does not know 

(nor, for that matter, does the expert always know) just which data are essential and which 
may be neglected. Even though not all of the data may turn out to have been necessary, as a 
general rule, time is saved in the end if all the usual data are prepared as a regular preliminary 
to the solution of most cryptograms. 

h. Jlrst, the cryptogram is recopied in the form of a work sheet. This sheet should be of a 
good quality of paper so as to withstand considerable erasure. If the cryptogram is to be 
copied by hand, cross-section paper of K-inch squares is extremely useful. The writing should 
i be in ink, and plain, carefully made roman capital letters should be used in all cases. If the 

cryptogram is to be copied on a typewriter, the ribbon employed should be impregnated with an 
ink that will not smear or smudge under the hand. 

e. The arrangement of the characters of the cryptogram on the work sheet is a matter of 
considerable importance. If the cryptogram as fimt obtained is in groups of regular length 
(usually five characters to a group) and if the umliteral frequency distribution shows the crypto¬ 
gram to be monoalphabetic, the characters should be copied without regard to this grouping. 
It is advisable to allow two spaces between letters, and to write a constant number of letters 
; per line, approximately 25. At least two spaces, preferably three spaces, should be left between 

j; horizontal lines. Care should be taken to avoid crowding the letters in any case, for this is 

I : not only confusing to the eye but also mentally irritating when later it is found that not enough 

space has been left for making various sorts of marks or indications. If the cryptogram is origi¬ 
nally in what appears to be word lengths (and this is the case, as a rule, only with the cryptograms 
of amateurs), naturally it should be copied on the work sheet in the original groupings. If 
further study of a cryptogram shows that some special grouping is required, it is often best to 
recopy it on a fresh work sheet rather than to attempt to indicate the new grouping on the old 
work sheet. 

d. In order to be able to locate or refer to specific letters or groups of letters with speed, 
certainty, and without possibility of confusion, it is advisable to use coordinates applied to the 
lines and colunms of the text as it appears on the work sheet. To minimize possibility of con¬ 
fusion, it is best to apply letters to the horizontal lines of the text, numbers to the vertical columns. 
In referring to a letter the horizontal line in which the letter is located is usually given first. Thus, 
referring to the work sheet shown below, coordinates A17 designate the letter Y, the 17th letter 
in the first line. The letter I is usually omitted from the series of line indicators so as to avoid 
confusion with the figure 1. If lines are limited to 25 letters each, then each set of 100 letters of 
the text is automatically blocked off by remembering that 4 lines constitute 100 letters. 

e. Above each character of the cipher text may be some indication of the frequency of that 
character in the whole cryptogram. This indication may be the actual number of times the 


43 


character occurs, or, if colored pencils are used, the cipher letters may be divided up into three 
categories or groups—^high frequency, medium frequency, and low frequency. It is perhaps 
simpler, if clerical help is available, to indicate the actual frequencies. This saves constant 
reference to the frequency tables, which interrupts the train of thought, and saves considerable 
time in the end. 

/. After the special frequency distribution, explained in Par. 27 below, has been constructed, 
repetitions of di^aphs and trigraphs should be vmderscored. In so doing, the student should be 
particularly watchful of trigraphic repetitions which can be further extended into tetragraphs 
and polygraphs of greater length. Repetitions of more than ten diaracters should be set off by 
heavy vertical lines, as they indicate repeated phrases and are of considerable assistance in 
solution. If a repetition continues from one line to the next, put an arrow at the end of the 
underscore to signal this fact. Reversible digraphs should also be indicated by an underscore 
with an arrow pointing in both directions. Anything which strikes the eye as being peculiar, 
unusual, or significant as regards the distribution or recurrence of the characters should be 
noted. All these marks should, if convenient, be made with ink so as not to cause smudging. 
The work sheet will now appear as shown herewith (not all the repetitions axe underscored): 

1 3 8 4 S « 7 8 9 10 11 12 13 14 15 IS 17 18 19 30 31 22 33 24 28 


3 19 IS 22 IS 3 8 19 8 8 

k|eghtveagxx 

27. Triliteral-frqquency distributions.— a. In what has gone before, a type of frequency 
distribution known as a uniliteral frequency distribution was used. This, of course, shows only 
the number of times each individual letter occurs. In order to apply the normal digraphic and 


il 


10 19 23 35 

19 10 3 

10 

15 

5 

6 

3fi 

10 

19 

35 

23 

14 

10 

6 

19 

15 

4 

35 

23 

10 

S F D Z 

F I 0 

G 

H L P 

z 

F 

G 

z 

_D 

J. s 

p 

F H B 

z 

D 

S 

19 IS 18 23 

19 5 5 

5 

16 

23 

19 

19 

14 

IS 

J 

IS 

19 

16 

18 

22 

19 

8 

23 

35 

35 

G V H T 

F U P 

L 

V 

_D 

F 

G 

Y 

V J 

V 

F 

V H 

T 

G A 

D 

z 

z 

8 10 23 14 

23 35 14 

19 

35 

3 

35 

22 

19 

3 

22 

IS 

23 

85 

4 

23 

16 

19 

15 

23 

35 

A IT Y 

D Z Y 

F 

Z 

J 

Z 

T 

G 

P T 

V 

T 

z 

B 

-D 

X 

X 

Ji 

X 


33 19 8 10 

4 19 10 

23 

35 

14 

IS 

22 

8 

3 

10 

14 

16 

22 

3 

19 

IS 

3 

19 

85 

35 

D F X S 

B G I 

D 

Z 

Y 

V 

T 

X 

0 

I 

Y 

V 

T 

E 

F 

V 

M 

G 

z 

z 

23 U 5 S 

IB 8 35 

23 

19 

3 

IS 

22 

35 

8 

ip 

22 

14 

23 

36 

14 


23 

16 

19 

16 

T H L L 

V X Z 


I. 

M 

H 

X 

A. 


X 

X 

X 

X. 

X 

_Y 

B 

_D 

X 

F H 

22 35 23 19 

2 35 23 

35 

35 

3 

10 

8 

10 

10 

10 

35 

14 

19 

8 

16 

19 

10 

5 

19 

35 

,T Z D F 

K Z D 

z 

z 

J 

S 

X 

I 

s 

G 

Z 

Y 

G 

A 

V 

F 

s 

L 

G 

z 

23 22 15 15 

22 1 23 

35 

2 

10 

IS 

22 

14 

35 

23 

3 

35 

10 

10 

15 

23 

35 

8 

10 

23 

D T H H 

T C D 

Z 

R 

S 

V 

T 

Y 

z 

D 

0 

z 

F 

F 

il 

X 


A. 

I 

T, 

14 23 35 14 

19 8 IS 

23 

10 

35 

35 

22 

3 

15 

10 

22 

14 

35 

14 

10 

23 

35 

19 

16 

6 

,Y D Z Y 

G A V. 


G 

Z 

Z 

T 

K 

H 

I_ 

T_ 

Y 

Z 

Y 

s 

D 

Z 

G H 

u 

35 19 35 22 

19 5 6 

19 

23 

10 

8 

1 

19 

15 

g 

8 

10 

2 

5 

38 

23 

19 


10 

23 

Z F Z T 

GUP 

G D 

I 

X 

W 

G 

H 

X 

A 

S 

R 

U 



F 

U 

I 

D 




44 


trigraphic frequency data feiren in Appendix 1) to the solution of a cryptogram of the type now 
beii^ studied, it is obvious that the data with respect to digraphs and trigraphs occurring in the 
cryptogram should be compiled and ^ould be compared with the data for normal plain text. In 
order to accomplish this in suitable manner, it is advisable to construct a slightly more com¬ 
plicated form of distribution termed a trUiteroL frequency distribution.* 

b. Given a cryptogram of 50 or more letters and the task of determining what taigraphs are 
present in the crjrptogram, there are three ways in which the data may be arranged or assembled. 
One may require that the data show (1) each letter with its two succeeding letters; (2) each letter 
with its two preceding letters; (3) each letter with one preceding letter and one succeeding letter. 

c. A distribution of the first of the three foregoing types may be deagnated as a “tailiteral 
frequency distribution showing two sufiixes”; the second type may be designated as a “tri¬ 
literal frequency distribution showing two prefixes”; the third type may be designated as 
a “triliteral frequency distribution showing one prefix and one suffix.” Quadiiliteral and 
pentaliteral frequency distributions may occasionally be foimd useful. 

d. Which of these three arrangements is to be employed at a specific time depends largely 
upon what the data are intended to show. For present purposes, in connection with the solution 
of a monoalphabetic.substitution cipher employing a mixed alphabet, possibly the third arrange¬ 
ment, that showing one prefix and one suflax, is most satisfactory. 

e. It is convenient to use K-iiich cross-section paper for the construction of a triliteral fre¬ 
quency distribution ill the form of a ffistribution ^owh^ crests and troughs, such as that in 
Figure 14. In that figme the prefix to each letter to be recorded is inserted in the left half of the 
ceU directly above the cipher letter bemg rewrded; ttie suffix to each letter is inserted in the right 
half of the cell directly above the letter being recorded; and in each case the prefix and the 
suffix to the letter bc^ recorded occupy the same cell, the prefix being directly to the left of the 
suflSx. The number in parentheses gives the total frequency for each letter. 

• Heretofore such a distribution has been termed a “trigraphic frequency table.” It is thought that the word 
“triliteral” is more suitable, to correspond with the designation “uniliteral” in the case of the disUibution of the 
single letters. A trigraphic distribution of A B C D E F would consider only the trigraphs ABC and DBF, 
whereas a triliteral distribution would consider the groups A B C, B C D, C D E, and D E F. (See also Par. lid.) 
The use of the word “distribution” to replace the word “table” has already been explained. 



ZI SG ZS VA ZG SV VT GD ZS HL DZ UL 

ZI ZD ZY DG ZI FZ FB AT ZZ TH PV FH XI SF 

GD HZ TD FZ TF SD OH GL FO W FZ HP VG IG LZ 





46 


47 


y. The trilitetal frequency distribution is now to be examined with a view to ascertaining 
what digraphs and trigraphs occur two or more times in the cryptogram. Consider the pair 
of columns containing the prefixes and suffixes to D, in the distribution, as shown in Fig. 14. 
This pair of columns shows that the following digraphs appear in the cryptogram: 


Digraphs hosed on prefixes {arranged 
as one reads up ihe column) 

FD, ZD. ZD, VD. AD, YD, BD, 

ZD, ID, ZD, YD, BD, ZD, ZD, 

ZD, CD, ZD, YD, VD, SD, GD, 

ZD, ID 


Digraphs based on suffixes {arranged 
as one reads up the column) 

DZ, DY, DS, DF, DZ, DZ, DV, 

DF, DZ, DF, DZ, DV, DF, DZ, 

DT, DZ, DO, DZ, DG, DZ, DI, 

DF, DE 


The nature of the triliteral frequency distribution is such that in finding what digraphs are 
present in the cryptogram it is immaterial whether the prefixes or the suflaxes to the cipher 
letters are studied, so long as one is consistent in the study. For example, in the foregoing list of 
digraphs based on the prefixes to Do, the digraphs FD, ZD, ZD, VD, etc., are found; if now, the 
student will refer to the sufllxea of F*, Z*, Vo, etc., he will find the very same digraphs indicated. 
This being the case, the question may be raised as to what value there is in listing both the 
prefixes and the suflBxes to the cipher letters. The answer is that by so doing the tiigraphs are 
indicated at the same time. For example, in the case of Do, the following trigraphs are indicated: 
FDZ, ZDY, ZDS, VDF, ADZ, YDZ, BDV, ZDF, IDZ, ZDF, YDZ, BDV, ZDF, 
pZ, ZDT, CDZ, ZDO, YDZ, VDG, SDZ, GDI, ZDF, IDE. 

■ g^ The repeated digraphs and trigraphs can now be found quite readily. Thus, in the case 
of De, ;examining the list of digraphs based on suflaxes, the following repetitions are noted: 

DZ appears 9 times 
DF appears 5 times 
DV appears 2 times 

Evam*»ing the trigraphs with Do as central letter, the following repetitions are noted: 

ZDF appears 4 times 
YDZ appears 3 times 
BDV appears 2 times 

A, It is unnecessary, of course, to go through the detailed procedure set forth in the pre¬ 
ceding subparagraphs in order to find all the repeated digraphs and trigraphs. The repeated 
trigraphs with D, as central letter can be found merely from an mspection of the prefixes and 
suffixes opposite Do in the distribution. It is necessary only to find those cases in which two or 
more prefixes are identical at the same time that the siffixes are identical. For example, the 
distribution shows at once that in four cases the prefix to Do is Zo at the same time that the 
sufi^ to this letter is Fo. Hence, the trigraph ZDF appears four times. The repeated tiigraphs 
may all be foimd in this maimer. 

i. The most frequently repeated digraphs and trigraphs are then assembled in what is 
termed a condensed table of repetitions, so as to bring this information prominently before the eye. 
As a rule, digraphs which occur less than four or five times, and trigraphs which occur less than 
three or four times may be omitted from the condensed table as being relatively of no importance 
in the study of repetitions. In the condensed table the frequencies of the individual letters 
forming the most important digraphs, trigraphs, etc., should be indicated. 

28. Classifying the cipher letters into vowels and consonants.— a. Before proceeding to a 
detailed analysis of the repeated digraphs and trigraphs, a very important step can be taken which 
will be of assistance not only in the analysis of the repetitions but also in the final solution of 
the cryptogram. This step concerns the classification of the high-frequency letters into two 


groups—vowels and consonants. For if the cryptanalyst can quickly ascertain the equivalents 
of the four vowels, A, E, I, and 0, and of only the four consonants, N, R, S, and T, he will then 
have the values of approximately two-thirds of all the cipher letters that occur in the cryptogram; 
the values of the remaining letters can almost be filled in automatically. 

b. The basis for the classification will be found to rest upon a comparatively simple phe¬ 
nomenon: the associational or combinatory behavior of vowels is, in general, quite different 
from that of consonants. If an examination be made of Table 7-B in Appendix 1, showing the 
relative order of frequency of the 18 digraphs composing 25 percent of English telegraphic text, 
it will be seen that the letter E enters into the composition of 9 of the 18 digraphs; that is, in 
exactly half of all the cases the letter E is one of the two letters forming the digraph. The 
digraphs containing E are as follovre: 

ED EN ER ES 

NE RE SE TE VE 

The remaining nine digraphs are as follows: 

AN ND OR ST 
IN NT TH 

ON TO 

c. None of the 18 digraphs is a combination of vowels. Note now that of the 9 combinations 
with E, 7 are with the consonants N, R, S, and T, one is with D, one is with V, and none is with any 
vowel. In other words, Ep combines most readily with consonants but not with other vowels, or 
even with itself. Using the terms often employed in the chemical analogy, E shows a great 
“affinity” for the consonants N, R, S, T, but not for the vowels. Therefore, if the letters of highest 
frequency occurring in a given cryptogram are listed, together with the number of times each of 
them combines with the cipher equivalent of Ep, those which show considerable combining power 
or affinity for the cipher equivalent of Ep may be assumed to be the cipher equivalents of N, R, S, 
Tp; those which do not show any affinity for the cipher equivalent of Ep may be assumed to be the 
cipher equivalents of A, I, 0, Up. Applying these principles to the problem in hand, and examin¬ 
ing the triliteral frequency distribution, it is quite certain that Ze=Ep, not only because Z, is the 
letter of highest frequency, but also because it combines with several other high-frequency letters, 
such as Do, F,, Go, etc. The nine letters of next highest frequency are: 

23 22 19 ID IS 18 U 10 10 

DTFGVHYSI 


Let the combinations these letters form with Zg be indicated in the following manner: 

Number of times Z, occurs as prefix.. § 5 5 g 

apher Letter.__ D(23) T(22) F(19) G(19) V(16) H(15) Y(14) S(10) 1(10) 

Number of times Z* occurs as suffix.. 5 ^ ^ 


d. Consider D,. It occurs 23 times in the message and 18 of those times it is combined with 
Zo, 9 times in the form Z,Do (=E0p), and 9 times in the form DoZo (=0Ep). It is clear that D, 
must be a consonant. In the same way, consider To, which shows 9 combinations with Zo, 4 in the 
form ZoTo (=E0p) and 6 in the form ToZo (=0Ep). The letter T* appears to represent a consonant, 
as do also the letters Fg, G,, and Y,. On the other hand, consider Vg, occurring in all 16 times but 
never in combination with Zg; it appears to represent a vowel, as do also the letters Hg, S*, and Ig. 
So far, then, the following classification would seem logical: 

Vowds Coruonanis 

Zg( = Ep), Vg, Hg, Sg, Ig Dg, Tg, Fg, Gg, Yg 



48 


29. Further aaalysis of> the letters representing vewels and consonants.— a. Op is usually 
the vowel of second highest frequency. Is it possible to determine which of the letters V, H, S, I« 
is the cipher equivalent of Op? Let reference be made again to Table 6 in Appendix 1, where it 
is seen that the 10 most frequently occurring diphthongs are: 

Diphthong._10 OU EA El AI IE AU EO AY UE 

Frequency_41 37 35 27 17 13 13 12 12 11 

If V, H, S, I, are really the cipher equivalents of A, I, 0, Up (not respectively), perhaps it is possible 
to determine which is which by examining the combinations they make among themadves and with 
Z, (=Ep). Let the combinations of V, H, S, I, and Z that occur in the message be listed. There 
are only the following: 

ZZo—4 HI—1 
VH —2 SV—1 
HH —1 IS—1 

ZZ, is of course EEp. Note the doublet HHoj if Ho is a vowel, then the chances are excellent that 
Ho=0p because the doublets AAp, IIpVUUp, are practically non-existent, whereas the double vowel 
combination OOp is of next highest frequency to the double vowel combination EEp. If Ho=0p, 
then Vo must be Ip because the digraph VHo occurring two times in the message could hardly be 
AOp, or UO^, whereas the diphthong lOp is the one of high frequency in English. So far then, the 
tentative (because so far unverified) results of the analysis are as follows: 

Z.=Ep H,=0p V,=Ip 

This leaves only two letters, and S, (already classified as vowels) to be separated into Ap and 
Up. Note the digraphs: 

Hie=oep 

SVe=0Ip 

is,=eep 

Only two alternatives are open: 

(1) Either Ie==Ap and Sc=Up, 

(2) Or Ie=Up and So=Ap. 

If the first alternative is selected, then 

HIe=0Ap 

SVe=UIp 

ISo=AUp 

If the second alternative is selected, then 


HIo=0Up 

SV„=AIp 

ISo=UAp 


The eye finds it difficult to choose between these alternatives; but suppose the frequency values of 
the plain-text diphthongs as given in Table 6 of Appendix 1 are added for each of these alternatives, 
giving the following: 


HIc=0Ap, frequency value= 7 
SVo=UIp, frequency value= 5 
ISc=AUp, frequency value=13 


HIo=0Up, frequency value=37 
SVe=AIp, frequency value=17 
ISo=UAp, frequency value= 5 


Mathematically, the second alternative is more than twice as probable as the first. Let it be 
assumed to be correct and the following (stUl tentative) values are now at hand: 

Z.=Ep Ho=Op Ve=Ip So=Ap Ic=Up 

b. Attention is now directed to the letters classified as consonants. How far is it possible 
to ascertain their values? The letter D„, from considerations of frequency alone, would seem 
to be Tp, but its frequency, 23, is not considerably greater than that for T,. It is not much 
greater than that for Fp or G*, with a frequency of 19 each. But perhaps it is possible to ascer¬ 
tain not the value of one letter alone but of two letters at one stroke. To do this one may make 
use of a tetragraph of considerable importance in English, viz, TIONp. For if the analysis per¬ 
taining to the vowels is correct, and if VH,=I0p, then an examination of the letters immediately 
before and after the digraph VH, in the cipher text might disclose both Tp and Np. Reference 
to the text gives the following: 

GVHT, FVHTo 

eiO0p 0IO0P 

The letter T* follows VHp in both cases and very probably indicates that T,=Np; but as to whether 
Gp or Fp equals Tp cannot be decided. However, two conclusions are clear: first, the letter Dp 
is neither Tp nor Np, from which it follows that it must be either Rp or Sp; second, the letters 
Gp and Fp must be either Tp and Sp, respectively, or Sp and Tp, respectively, because the only 
tetragraphs usually found (in English) containing the diphthong lOp as central letters are SIONp 
and TIONp. This in turn means that as regards Dp, the latter cannot be either Rp or Sp,* it must 
be Rp, a conclusion which is corroborated by the fact that ZDp (=ERp) and DZp (=REp) occur 9 
times each. Thus far, then, the identifications, when inserted in an erhciphering alphabet, are 
as follows: 

Plain_A BCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher.S Z V TH DGFI 

F G 

80. Substituting deduced values in the cryptogram.— a. Thus far the analysis has been 
almost purely hypothetical, for as yet not a single one of the values deduced from the foregoing 
analysis has been tried out in the cryptogram. It is high time that this be done, because the 
final test of the validity of the hypotheses, assumptions, and identifications made in any crypto¬ 
graphic study is, after aU, only this: do these hypotheses, assumptions, and identifications 
ultimately yield verifiable, intelligible plain-text when consistently applied to the cipher text? 

h. At the present stage in the process, since there are at hand the assumed values of but 9 
out of the 25 letters that appear, it is obvious that a continuous “reading” of the‘cryptogram 
can certainly not be expected from a mere insertion of the values of the 9 letters. However, the 
substitution of these values should do two things. First, it should immediately disclose the 
fragments, outlines, or “skeletons” of “good” words in the text; and second, it should disclose 
no places in the text where “impossible” sequences of letters are established. . By the first is 
meant that the partially deciphered text should show the outlines or skeletons of words such 
as may be expected to be found in the communication; this will become quite clear in the next 
subparagraph. By the second is meant that sequences, such as “AOOEN” or “TNRSENO” or the 
like, obviously not possible or extremely unusual in normal English text, must not result from 
the substitution of the tentative identifications resulting from the analysis. The appearance 
of several such extremely unusual or impossible sequences at once signifies that pne or more of 
the assumed values is incorrect. 


Total. 


25 


Total. 












51 


5d 

c. Here are the results of substituting the nine values which have been deduced by the 
reasoning based on a classification of the high-frequency letters into vowels and consonants 
and the study of the members of the two groups: 


) 11 13 1 


I IS 17 IS M so 31 22 1 


10 18 23 36 U 10 3 19 16 6 6 36 19 19 36 23 11 10 6 19 16 4 36 23 10 

SFDZFIOGHLPZFGZDYSPFHBZDS 
ATRET SO ETSER A TO ERA 
S S T ST S 

19 16 16 23 10 8 6 6 18 23 10 19 14 18 3 IS 19 16 16 33 19 8 23 36 36 

GVHTFUPLVDFGYVJVFVHTGADZZ 
SIONT IRTS I ITIONS REE 

T S ST S T 

8 10 22 14 23 36 14 10 36 3 86 22 19 6 22 16 22 36 4 23 16 19 16 22 36 

AITYDZYFZJZTGPTVTZBDVFHTZ 
N RE TE ENS NINE RITONE 
ST S 

23 19 8 10 4 10 10 33 36 14 16 33 8 3 10 14 16 23 3 19 IS 2 19 33 36 

DFXSBGIDZYVTXOIYVTEFVMGZZ 
RT A S RE IN IN TI SEE 

ST S T 

22 16 5 6 16 8 36 23 19 3 16 22 35 8 10 23 14 23 36 14 4 33 16 19 16 

THLLVXZDFMHTZAITYDZYBDVFH 
NO I ERT ONE N RE RITO 
S S 

23 36 23 19 3 36 23 86 36 3 10 8 10 10 19 36 14 19 8 16 19 10 6 19 36 

TZDFKZDZZJSXISGZYGAVFSLGZ 
NERT EREE A ASE S ITA SE 
S T T S T 

23 22 16 16 22 1 23 36 2 10 16 22 14 36 23 3 36 19 10 18 22 36 8 10 22 

DTHHTCDZRSVTYZDOZFFHTZAIT 
RNOON RE AIN ER ETTONE N 
S S 

14 23 36 14 19 8 16 23 19 36 36 22 2 16 10 32 14 86 14 10 23 36 19 16 6 

YDZYGAVDGZZTKHITYZYSDZGHU 
RE S IRSEEN 0 N E ARESO 
T T T 

36 19 36 22 19 6 6 19 23 10 8 1 24 16 8 8 10 3 6 36 23 19 6 10 23 

ZFZTGUPGDIXWGHXASRUZDFUID 
ETENS SR SO A ERT R 

S T T T S 

8 19 16 22 16 3 8 19 8 8 

EGHTVEAGXX 
S 0 N I S 

T T 


J 


d. No impossible sequences are brought to light, and, moreover, several long words, nearly 
complete, stand out in the text. Note the following portions: 

A21 

hbzdsgvhtXf 

(1) 0?ERASI0NT 

T S 

C16 

TVTZBDVFHTZDF 

(2) NINE?RITONERT 

S S 

F23 

SLGZDTHHT 

(3) A?SERN00N 

T 

The words are obviously OPERATIONS, NINE PRISONERS, and AFTERNOON. The value G. si 
clearly Tp; that of F, is Sp; and the following additional values are certain: 

Bp=Pp L,=Fp 

31. Completing the solution,— a. Each time an additional value is obtained, substitution 
is at once made throughout the cryptogram. This leads to the determination of further values, 
in an ever-widening circle, until aU the identifications are firmly and finally established, and the 
message is completely solved. In this case the decipherment is as follows: 

1 3 3 4 6 6 7 8 0 10 11 13 13 14 16 16 17 18 19 20 31 23 23 24 26 


SFDZFIOGHLPZF 

ASRESULTOFYES 

GVHTFUPLVDFGY 

TIONSBYFIRSTD 

AITYDZYFZJZTG 

HUNDREDSEVENT 

DFXSBGIDZYVTX 

RSCAPTUREDINC 

THLLVXZDFMHTZ 

NOFFICERSXONE 

TZDFKZDZZJSXI 

NERSWEREEVACU 

DTHHTCDZRSVTY 

RNOONQREMAIND 

YDZYGAVDGZZTK 

DREDTHIRTEENW 


GZDYSPFHBZDS 

TERDAYSOPERA 

VJVFVHTGADZZ 

IVISIONTHREE 

PTVTZBDVFHTZ 

YNINEPRISONE 

OIYVTEFVMGZZ 

LUDINGSIXTEE 

AITYDZYBDVFH 

HUNDREDPRISO 

SGZYGAVFSLGZ 

ATEDTHISAFTE 

ZDOZFFHTZAIT 

ERLESSONEHUN 

HITYZYSDZGHU 

OUNDEDARETOB 


ZFZTGUPGDIXWGHXASRUZDFUID 

esentbytrucktochambersbur 

EGHTVEAGXX 

GTONIGHTXX 








Message: AS RESULT OF YESTERDAYS OPERATIONS BY FIRST DIVISION THREE 
HUNDRED SEVENTY NINE PRISONERS CAPTURED INCLUDING SIXTEEN OFFICERS ONE 
HUNDRED PRISONERS WERE EVACUATED THIS AFTERNOON REMAINDER LESS ONE HUNDRED ^ 

THIRTEEN WOUNDED ARE TO BE SENT BY TRUCK TO CHAMBERSBURG TONIGHT \ 

b. The solution should, as a rule, not be considered complete imtU an attempt has been 
made to discover aU the elements underlying the general system and the specific key to a message. 

In this case, there is no need to delve further into the general system, for it is merely one of 
monoalphabetic substitution with a mixed cipher alphabet. It is necessary or advisable, how¬ 
ever, to reconstruct the cipher alphabet because this may give clues that later may become 
valuable. 

c. Cipher alphabets should, as a rule, be reconstructed by the cryptanalyst in the form of 
enciphering alphabets because they will then usually be in the form in which the encipherer 
used them. This is important for two reasons. First, if the sequence in the cipher component 
gives evidence of system in its construction or if it yields clues pointing toward its derivation 
from a keyword or a key-phrase, this may often corroborate the identifications already made 
and may lead directly to additional identifications. A word or two of explanation is advisable 
here. For example, refer to the skeletonized enciphering alphabet given at the end of par. 296: 

Plain........_ ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher......:.... S Z V TH DGFI 

F G 

Suppose the cryptanalyst, looking at the sequence DGFI or DFGI in the cipher component, sus¬ 
pects the presence of a keyword-mixed alphabet. Then DFGI is certainly a more plausible 
sequence than DGFI. Again, noting the sequence S . . . Z . . . V . . . . TH . , D, he might 
have an idea that the keyword begins after the Z and that the TH is followed hy AB or BC. This 
would mean that either P, Qp=A, Bo or B, Co. Assuming that P, Qb=A, B„ he refers to the fre¬ 
quency distribution and finds that the assumptions Pp==Ao and Qp=Bo are not good; on the other 
hand, naanming that P, Qp=B, Co, the frequency distribution gives excellent corroboration. 

A trial of these values would materially hasten solution because it is often the case in crypt¬ 
analysis that if the value of a very low-frequency letter can be surely established it will yield 
clues to other values very quickly. Thus, if Qp is definitely identified it almost invariably will 
identify Up, and will give clues to the letter following the Up, since it must be a vowel. In the 
case imder discussion the identification PQp=BCo would have turned out to be correct. For the 
foregoing reason an attempt should always be made in the early stages of the analysis to deter¬ 
mine, if possible, the basis of construction or derivation of the cipher alphabet; as a rule this 
can be done only by means of the enciphering alphabet, and not the deciphering alphabet. For 
example, the skeletonized deciphering alphabet corresponding to the enciphering alphabet 
directly above is as follows: 

Cipher.. ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Plain_ RTSOU ANI E 

S T 

Here no evidences of a keyword-mixed alphabet are seen at all. However, if the enciphering 
alphabet has been examined and shows no evidences of systematic construction, the deciphering 
alphabet should then be examined with this in view, because occasionally it is the deciphering 
alphabet which shows the presence of a key or keying element, or which has been systematically 
derived from a word or phrase. The second reason why it is important to try to discover the basis 


of construction or derivation of the cipher alphabet is that it affords clues to the general type of 
keywords or keying elements employed by the enemy. This is a psychological factor, of course, 
and may be of assistance in subsequent studies of bis traffic. It merely gives a clue to the general 
type of thinking indulged in by certain of his cryptographers. 

d. In the case of the foregoing solution, the complete enciphering alphabet is found to be as 
follows: 


Plain. ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher.. SUXYZLEAVNWORTHBCDFGIJKMP 


Obviously, the letter Q, which is the only letter not appearing in the cryptogram, should follow 
P in the cipher component. Note now that the lattSr is based upon the keyword LEAVENWORTH, 
and that this particular cipher alphabet has been composed by shifting the mixed sequence based 
upon this keyword five intervals to the right so that the key for the message is Ap=Sc. Note 
also that the deciphering alphabet fails to give any evidence of keyword construction based upon 
the word LEAVENWORTH. 


Qpher... ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Plain_ HPQRGSTOUVWFXJLYZMANBIKCDE 


e. If neither the enciphering or the deciphering alphabet exhibits characteristics which 
give indication of derivation from a keyword by some form of mixing or disarrangement, the 
latter is nevertheless not finally excluded as a possibility. The student is referred to Section IX 
of Elementary Military Cryptography, wherein will be found methods for deriving mixed alphabets 
by transposition methods apphed to keyword-mixed alphabets. For the reconstruction of such 
mixed alphabets the cryptanalyst must use ingenuity and a knowledge of the more common 
methods of suppressing the appearance of keywords in the mixed alphabets. 

32. General notes on the foregoing solution.— a. The example solved above is admittedly 
a more or less artificial illustration of the steps in analysis, made so in order to demonstrate 
general principles. It was easy to solve because the frequencies of the various cipher letters cor¬ 
responded quite well with the normal or expected frequencies. However, all cryptograms of 
the same monoalphabetical nature can be solved along the same general lines, after more or less 
experimentation, depending upon the length of the cryptogram, the skill, and the experience of 
the cryptanalyst. 

h. It is no cause for discouragement if the student’s initial attempts to solve a cryptogram of 
this type require much more time and effort than were apparently required in solving the fore¬ 
going purely illustrative example. It is indeed rarely the case that every assumption made by the 
cryptanalyst proves in the end to have been correct; more often is it the case that a good many 
of his initial assumptions are incorrect, and that he loses much time in casting out the erroneous 
ones. The speed and facility with which this elimination process is conducted is in many cases 
all that distinguishes the expert from the novice. 

c. Nor will the student always find that the initial classification into vowels and consonants 
can be accomplished as easily and quickly as was apparently the case in the illustrative example. 
The principles indicated are very general in their nature and applicability, and there are, in 
addition, some other principles that may be brought to bear in case of difficulty. Of these, per¬ 
haps the most useful are the following: 

(1) In normal English it is unusual .to find two or three consonants in succession, each of high 
frequency. If in a cryptogram a succession of three or four letters of high-frequency appear in 
succession, it is practic^y certain that at least one of these represents a vowel.® 

® Sequences of seven consonants are not impossible, however, as in STR ENGTH THR OUGH. 














54 


55 


(2) Successions of three vowels are rather unusual in English.* Practically the only time 
this happens is when a word ends in two vowels and the next word begins with a vowel.® 

(3) When two letters already classified as vowel-equivalents are separated by a sequence of 
six or more letters, it is either the case that one of the supposed vowel-equivalents is incorrect, 
or else that one or more of the intermediate letters is a vowel-equivalent.® 

(4) Reference to Table 7-B of Appendix 1 discloses the following: 

Diftribution of first 18 digraphs forming tB percent of English text 


Number of consonaat-consonant digraphs--- 4 

Number of consonant-vowel digraphs___:_ 6 

Number of vowel-consonant digraphs_______ 8 

Number of vowel-vowel digraphs___^ 0 

Distribution of first 6S digraphs forming BO percent of English text 

Number of consonant-consonant digraphs___ 8 

Number of consonant-vowel digraphs__ 23 

Number of vowel-consonant digraphs_ 18 

Number of vowel-vowel digraphs_____ 4 


The latter tabulation shows that of the first 53 digraphs which form 50 percent of English text, 

41 of them, that is, over 75 percent, are combinations of a vowel with a consonant. In short, 
in normal English the vowels and the high-frequency consonants are in the long run dis¬ 
tributed fidrly evenly and regularly throughout the text. 

(5) As a rule, repetitions of trigraphs in the cipher text are composed of high-frequency 
letters forming high-frequency combinations. The latter practically always contain at least one 
vowel; in fact, if reference is made to Table 10-A of Appendix 1, it be noted that 36 of the 56 
trigraphs having a frequency of 100 or more contain one vowel, 17 of them contain two vowels, 
and only three of them contain no vowel. In the case of tetragraph repetitions. Table 11-A of 
Appendix 1 shows that no tetragraph listed therein fails to contain at least one vowel; 28 of them 
contain one vowel, 25 contain two vowels, and 2 contain three vowels. 

(6) Quite frequently when two known vowel-equivalents are separated by rix or more letters 
none of which seems to be of sufficiently high frequency to represent one of the vowels A E I 0, 
the chances are good that the cipher-equivalent of the vowel U or Y is present. 

(7) The letter Q is invariably followed by U; the letters J and V are invariably followed by a 
vowel, 

d. In the foregoing example the amount of experimentation or “cutting and fitting” was 
practically nil. (This is not true of real cases as a rule.) Where such experimentation b neces- 

< Note that the word RADIOED, past tense of the verb RADIO, is coming into usage. 

• A sequence of seven vowels is not impossible, however, as in THE WAY YOU EAR N. 

‘ Some cryptanalysts place a good deal of emphasis upon this principle as a method of locating the remaining 
vowels after the first two or three have been located. They recommend that the latter be underlined throughout 
the text and then all sequences of five or more letters showing no underlines be studied attentively. Certain ;, 

letters which occur in several such sequences are sure to bo vowels. An arithmetical aid in the study is as follows; j | 

Take a letter thought to be a good possibility as the cipher equivalent of a vowel (hereafter termed a possible ,i I 

vowel-equivalent) and find the length of each interval from the possible vowel-equivalent to the next known (fairly 11 

surely determined) vowel-equivalent. Multiply the interval by the number of times this Interval is found. Add l ! 

the products and divide by the total number of intervals considered. This will give the mean interval for that \ 

possible vowel-equivalent. Do the same for all the other possible vowel-equivalents. The one for which the 
mean is the greatest is most probably a vowel-equivalent. Underline this letter throughout the text and repeat j] 

the process for locating additional vowel-equivalents, if any remain to be located. I 


sary, the mderscoring of all repetitions of several letters is very essential, as it calls attention to 
pecnliarities of structure that often yield clues. 

e. After a few basic assumptions of values have been made, if short words or skeletons of 
words do not become manifest, it is necessary to make further assmnptions for unidentified letters. 
Thb is accomplished most often by assuming a word.' Now there are two places in every message 
which lend themselves more readily to successful attack by the assumption of words than do 
any other places—the very beginning and the very end of the message. The reason is quite 
obvious, for although words may begin or end with almost any letter of the alphabet, they 
usuaUy begin and end with but a few very common digraphs and trigraphs. Very often the 
association of letters in peculiar combinations will enable the student to note where one word 
ends and the next begins. For example suppose, E, N, S, and T have been definitely identified, 
and a sequence like the following is foxmd in a cryptogram: 

. . .ENTSNE. . . 

Obviously the break between two words should fall either after the S of E N T S or after the T 
ofENT, BO that two possibilities are offered: . . . ENTS/NE . . ., or . . . ENT/SNE 
, . .. Since in English there are very few words with the initial trigraph S N E, it is most 
likely that the proper division is , , . E N T S / N E . . .. Obviously, when several word 
divisions have been found, the solution is more readily achieved because of the greater ease with 
which assumptions of additional new values may be made. 

83. The “probable word” method; its value and applicability.— a. In practically all cryptan- 
alytic studies, short-cuts can often be made by assuming the presence of certain words in the 
message under study. Some writers attach so much value to this kind of an “attack from the 
rear” that they practically elevate it to the position of a method and call it the “intuitive method” 
or the “probable-word method.” It is, of course, merely a refinement of what in every-day 
lai^age is called “assuming” or “guessing” a word in the message. The value of m airing a 
“good guess” can hardly be overestimated, and the cryptanalyst should never feel that he is 
accomplishing a solution by an illegitimate subterftige when he has made a fortunate guess 
leading to solution. A correct assumption as to plain text will often save hours or days of labor, 
and sometimes there is no alternative but to try to “guess a word”, for occasionally a system is 
encountered the solution of which is absolutely dependent upon this artifice. 

b. The expression “good guess” is used advisedly. For it is “good” in two respects. First, 
the cryptanalyst must use care in making his assumptions as to plain-text words. In t.bia he 
must be guided by extraneous circumstances leading to the assumption of ‘prohahlc words—^not 
just any words that come to his mind. Therefore he must use his imagination but he must 
nevertheless carefully control it by the exercise of good judgment. Second, only if the “guess” 
is correct and leads to solution, or at least puts him on the road to solution, is it a good guess. 
But, while realizing the usefulness and the time and labor-saving features of a solution by assum¬ 
ing a probable word, the cryptanalyst should exercise discretion in regard to how long he may 
continue in his efforts with this method. Sometimes he may actually waste time by adhering 
to the method too long, if straightforward, methodical analysis will yield results more quickly. 

c. Obviously, the “probable-word” method has much more applicability when working 
upon material the general nature of which is known, than when working upon more or less 
isolated commimications exchanged between correspondents concerning whom or whose activities 

' This process does not involve anything more mysterious than ordinary, logical reasoning; there is nothing 
of the subnormal or supernormal about it. If cryptanalytic success seems to require processes akin to those of 
medieval magic, if “hocus-pocus” is much to the fore, the student should begin to look for items that the claimant 
of such success has carefully hidden from view, for the mystification of the uninitiated. (See Par. 33 in this 
connection.) 













56 


nothing is known. For in the latter case there is little or nothing that the imagination can seke 
upon as a backgroimd or basis for the assumptions.* 

d. Very frequently, the choice of probable words is aided or limited by the number and 
positions of repeated letters. These repetitions may be patent —that is, externally visible in 
the cryptographic text as it originally stands—or they may be latent —that is, externally invisible 
but susceptible of being made patent as a result of the analysis. For example, in a monoalpha- 
betic substitution cipher, such as that discussed in the preceding paragraph, the repeated letters 
are directly exhibited in the cryptogram; later the student will encounter many cases in which 
the repetitions axe latent, but are made patent by the analytical process. When the repetitions 
are patent, then the pattern ox Jormvla to which the repeated letters conform is of direct use 
in assuming plain>text words; and when the text is in word-lengths, the pattern is obviously of 
even greater assistance. Suppose the cryptanalyst is dealing with military text, in which case 
he may expect such words as DIVISION, BATTALION, etc., to be present in the text. The 

1 positions of the repeated letter I in DIVISION, of the reversible digraph AT, TA in BATTALION, 

I and so on, constitute for the experienced cryptanalyst tell-tale indications of the presence of 

i these words, even when the text is not divided up into its original word lengths. 

e. The important aid that a study of word patterns can afford in cryptanalysis warrants the 
use of definite terminology and tie eetablishment of certain data having a bearing thereon. The 

[ phenomenon herein under discussion, namely, that many words are of such construction as 

regards the number and positions of repeated letters as to make them readily identifiable, will he 
I termed (from the Greek “idios” tone's own, individual, peculiar4-“niorphe”=form). 

I j Words whidi show this phenomenon will be termed idiomorphic. It will be useful to deal with 

I the idiomorphisins symbolically and systematically as described below. 

I /. When dealing with ciyptt^ams in which the word lengths are determined or specifically 

• shown, it is convenient to indicate their lengths and their repeated letters in some easily rec(^- 

nized manner or by formulas. This is exemplified, in the case of the word DIVISION, by the 
formula ABCBDBEF; in the case of the word BATTALION, by the formula ABCCBDEFG. If the 
cryptanalyst, during the course of his studies, makes note of striking formulas he has encoun¬ 
tered, with ihe words which fit them, after some time he will have assembled a quite valuable 
body of data. And after more or less complete lists of such formulas have been established in 
some systematic arrangement, a rapid comparison of the idiomorphs in a specific cryptogram 
; with those in his lists will be feasible and will often lead to the assumption of the correct word. 

Such lists can be arranged according to word length, as shown herewith: 

3/aba : DID, EVE, EYE. 
abb : ADD, ALL, ILL, OFF, etc. 

4/abac : ARAB, AWAY, etc. 

abca : AREA, BOMB, DEAD, etc. 

abbc : . . . 

abcb : . . . 

etc. etc. 

• General Givierge in his Court de Cryptographie (p. 121) says: “However, expert cryptanalysts often 
employ such details as are cited above [in connection with assuming the presence of ‘probable words’], and the 
experience of the years 1914 to 1918, to cite only those, prove that in practice one often has at his disposal ele¬ 
ments of this nature, permitting assumptions much more audacious than those which served for the analysis 
of the last example. The reader would therefore be wrong in imagining that such fortuitous elements are 
encountered only in cryptographic works where the author deciphers a document that he himself enciphered. 

' Cryptographic correspondence, if it is extensive, and if sufficiently numerous working data are at hand, often 

s I furnishes elements so complete that an author would not dare use all of them in solving a problem for fear of 

1: being accused of obvious exaggeration.’’ 


57 




g. When dealing with cryptographic text in which the lengths of the words are not indicated 
or otherwise determinable, lists of the foregoing nature are not so useful as lists in which the 
words (or parts of words) are arranged according to the intervals between identical letters, in the 
following manner: 

1 Interval 
-DiD- 
-EvE- 
-EyE- 
dlvlsion 
revision 
etc. 

34. Solution of additional cryptograms produced by the same cipher component.—a. To 
return, after a rather long digression, to the cryptogram solved in pars. 28-31, once the cipher 
component of a cipher alphabet has been reconstructed, subsequent messages which have been 
enciphered by means of the same cipher component may be solved very readily, and without 
recourse to the principles of frequency, or application of the probable-word method. It has been 
seen that the illustrative cryptogram treated in paragraphs 24-31 was enciphered by juxtaposing 
the cipher component against the normal sequence so that Ap=Sc. It is obvious that the cipher 
component may be set against the plain component at any one of 26 different points of coinci¬ 
dence, each yielding a different cipher alphabet. After a cipher component has been reconstructed, 
however, it becomes a known sequence, and the method of converting the cipher letters into their 
plain-component equivalents and then completing the plain-component sequence begun by 
each equivalent can be applied to solve any cryptogram Which has been enciphered hy that 
cipher component. 

b. An example will serve to make the process clear. Suppose the following message, passing 
between the same two stations as before, was intercepted shortly after the first message had 
been solved: 

lYEWK CERNW OFOSE LFOOH EAZXX 

It is assumed that the same cipher component was used, but with a different key letter. First 
the initial two groups are converted into their plain-component equivalents by setting the 
cipher component against the normal sequence at any arbitrary point of coincidence. The 
initial letter of the former may as well be set against A of the latter, with the following result: 


Plain. .. ABCDEFGHIJKLMNOPQRSTUVWXYZ 

Cipher- LEAVNffORTHBCDFGIJKMPQSUXYZ 


Cryptogram.... lYEWK CERNW ... 

Equivalents.... PYBFRLBHEF ... 

The normal sequence initiated by each of these conversion equivalents is now completed, with 
the results shown in Fig. 15. Note the plain-text generatrix, CLOSEYOURS, which manifests 
itself without further analysis. The rest of the message may be read either by continuing the 


2 Intervals 5 Intervals Repeated digraphs 

AbbAcy AbeyAnce COCOa 

ArAbiA hAbitAble dERER 

AbiAtive lAborAtory ICICle 

AboArd AbreAst ININg 

-AciA- AbroAd bAGgAGe 

etc. etc. etc. 






1 ss 

same process, or, wiiat is even more simple, the key letter of the message may now he determined 
quite readily and the message deciphered by its means. 

lYEWKCERNW 
PYBFRLBHEF 
QZCGSMCIFG 
RADHTNDJGH 
SBEIUOEKHI 
TCFJVPFLIJ 
UDGKWQGMJK 
VEHLXRHNKL 
WFIMYSIOLM 
XGJNZTJPMN 
YHKOAUKQNO 
ZILPBVLROP 
AJMQCWMSPQ 
BKNRDXNTQR 
♦CLOSEYOURS 
DMPTFZPVST 
ENQUGAQWTU 
FORVHBRXUV 
G F S W I C S Y V W 
HQTXJDTZWX 

! IRUYKEUAXY 

I JSVZLFVBYZ 

I KTWAMGWCZA 

If LUXBNHXDAB 

^ MVYCOIYEBC 

NWZDPJZFCD 

= OXAEQKAGDE 

e. In order that the student may understand without question just what is involved in the 
latter step, that is, discovering the key letter after the first two or three groups have been deci¬ 
phered by the conversion-completion process, the foregoing example will be used. It was noted 

I that the first cipher group was finally deciphered as follows: 

^ Cipher._ I Y E W K 

Plain. CLOSE 

Now set the cipher component against the normal sequence so that Cp=I,. Thus: 

\ Plain . ABCDEFGHIJKLMNOPQRSTUVWXYZ 

I Cipher. fGIJKMPQSUXYZLEAVNWORTHBCD 

It is seen here that when Cp=I, then Ap=F.. This is the key for the entire message. The 
decipherment may be completed by direct reference to the foregoing cipher alphabet. Thus: 

Cipher.. lYEWK CERNW OFOSE LFOOH EAZXX 

Plain. CLOSE YOURS TATIO NATTW OPMXX 

Message: CLOSE YOUR STATION AT TWO PM 

1 d. The student should make sure that he understands the fundamental principles involved in 

this quick solution, for they are among the most important principles in cryptanalytics. How ire¬ 
ful they are will become clear as he progresses into more and more complex cryptanalytic studies. 


1 


Section VII 

MULTILITERAL SUBSTITUTION WITH SINGLE-EQUIVALENT CIPHER ALPHABETS 


Panctapb 

Analysis of multUiteral, monoalphabetic substitution systems_ 36 

Historically interesting examples- 36 


86. Analysis of mnltiliteral, monoalphabetic substitution systems.— a. Substitution methods 
in general may be classified into uniliteral and multihteral systems.* In the former there is a 
strict “one-to-one” correspondence between the length of the units of the plain and those of the 
cipher text; that is, each letter of the plain text is replaced by a single charactw in the cipher text. 
In the latter this correspondence is no longer I,,:!, but may be Ip: 2*, where each letter of the plain 
text is replaced by a combination of two characters in the cipher text; or Ip: 3 c, where a 3-character 
combination in the cipher text represents a single letter of the plain text, and so on. A cipher in 
which the correspondence of the Ip:!, type is termed uniliteral in character; one in which it is of 
the lp:2« type, biHteral; lp:3c, triUteral, and so on. Those beyond the Ip:!, type are classed to¬ 
gether as mvltiliteral. 

b. When a multiliteral system employs biliteral equivalents, the cipher alphabet is said to be 
bipartite. Such alphabets are composed of a set of 25 or 26 combinations of a limited number of 
characters taken in pairs. An example of such an alphabet is the following. 


Plain-.... 

_A 

B 

C 

D 

E 

F 

G 

H 

I 

J 

K 

L 

H 

Cipher. 

_WW 

WH 

WI 

WT 

WE 

HW 

HH 

HI 

HT 

HT 

HE 

IW 

IH 

Plain_ 

.N 

0 

P 

Q 

R 

S 

T 

U 

V 

W 

X 

Y 

Z 

Cipher_ 

_II 

IT 

IE 

TW 

TH 

TI 

TT 

TE 

EW 

EH 

El 

ET 

EE 


This alphabet is derived from the square shown in Mg. !5. 

( 2 ) 



W 

H 

I. 

T 

E 

W 

A 

B 

C 

D 

E 

H 

F 

G 

H 

I-J 

K 

(1) I 

JLi 

U 

N 

0 

P 

T 

Q 

R 

S 

T 

U 

E 

V 

W 

X 

Y 

Z 


Kioto* li. 


e. If a message is enciphered by means of the foregoing bipartite alphabet the cryptogram is 
still monoalphabetic in character. A frequency distribution based upon pairs of letters will 
I See Sec. VII, Advanced Military Cryptography. 




( 69 ) 

















61 


obviouslj- have all the characteristics of a simple, uniliteral distribution for a monoalphabetic 
substitution cipher. 

d. Ciphers of this type, as well as of those of the multiliteral (triliteral, quadraliteral, . . .) 
type are readily detected externally by virtue of the fact that the cryptographic text is composed 
of but a very limited nmnber of different characters. They are handled in exactly the same man¬ 
ner as are unihteral, monoalphabetic substitution ciphers. So long as the same character, or 
combination of characters, is always used to represent the same plain-text letter, and so long as a 
given letter of the plain text is always represented by the same character or combination of 
characters, the substitution is strictly monoalphabetic and can be handled in the simple manner 
described under Par. 31 of this text. 

e. An interesting example in which the cipher equivalents are quinqueliteral groups and yet 
the resulting cipher is strictly monoalphabetic in character is found in the cipher system invented 
by Sir Francis Bacon over 300 years ago. Despite its antiquity the system possesses certain 
featiu*es of merit which are well worth noting. Bacon’ proposed the foUowing cipher alphabet, 
composed of permutations of two elements taken five at a time: * 


A=aaaaa 

I-j=aba 2 ia 

R=baaaa 

B=aaaab 

K=;abaab 

S=baaab 

C=aaaba 

I^ab8tba 

T=baaba 

D=aaabb 

M=ababb 

Il-V=baabb 

E^aabaa 

N=abbaa 

W=;babaa 

Fssaabab 

Osabbab 

X=babab 

Gi=aabba 

P*=abbba 

Y=babba 

H=aabbb 

Q=abbbb 

Z»babbb 


If this were aU there were to Bacon’s invention it would be hardly worth bringing to attention. 
But what he pointed out, with great clarity and simple examples, was how such an alphabet 
might be used to convey a secret message by enfolding it in an innocent, external mess^e which 
might easily evade the strictest kind of censorship. As a very crude example, suppose that a 
message is written in capital and lower ease letters, any capital letter standing for kn “a” element 
of the cipher alphabet, and any small letter, for a “b” element. Then the external sentence 
"All is well with me today" can be made to contain the secret message "Help." Thus: 

ALl is WEIL WItH mE TodaY 

aab bb aaba aaba ba abbba 

H E L P 

Instead of emplosdng such an obvious device as capital and small letters, suppose that an “a" 
element be indicated by a very slight shading, or a very dightly heavier stroke. Then a secret 
message might easily be thus enfolded within an external message of exactly opposite meaning. 
The number of possible variations of this basic scheme is very high. The fact that the characters 


of the cryptographic text are hidden in some manner or other has, however, no effect upon the 
strict monoalphabeticity of the scheme. 

36. Historically interesting examples.—a. Two examples of historical interest will be cited 
in this cmmection as illustrations. During the campaign for the presidential election of 1876 
many cipher messages were exchanged between the Tilden managers and their agents in several 
states where the voting was hotly contested. Two years later the New York Tribune * exposed 
many irregularities in the campaign by publishing the decipherments of man y of these messages. 
Th^e decipherments were achieved by two investigators employed by the Tribime, and the 
plain text of the messages seems to show that filial attmnpts and measures to carry the election 
for Tilden were made by his managers. Here is one of the messages: 

JACKSONVILLE, Nov. 16 (1876). 

GEO. F. RANEY, Tallahassee. 

Ppyyemnsnyyypimashnsyyssitepaaenshns 
pensshnsmmplyysnppyeaapielssyeshainsssp 
eeiyyshnynsssyepiaanyitnsshyyspyypinsyy 
ssitemeipimmeisseiyye i ss i te i opyype e iaas s 
imaayespnsyyianssseissmmppnspinssnpinsim 
imyyitemyysspeyymmnsyyssitspyypeepppma 
aayypiit 
L'Engle goes up tomorrow. 

DANIEL. 


Examination of the message discloses that only ten different letters are used. It is probable, 
therefore, that what one has here is a cipher which employs a bipartite alphabet and in which 
combinations of two letters represent single letters of the plain text. The message is therefore 
rewritten in pairs and substitution of arbitrary letters for the pairs is made, as seen below: 

PP YY EM NS NY YY PI MA SH NS YY SS etc. 

A BCDEBFGHDB I etc. 

A triliteral frequency distribution is then made and analysis of the message along the linea 
illustrated in the preceding section of this text yields solution, as follows: 

. Jacksonville, Nov. 16. 

Geo. F. Raney, Tallahassee: 

Have Marble and Coyle telegraph for influential men from Delaware and Virginia. Indi¬ 
cations of weakening here. Press advantage and watch Board. L’Engle goes up tomorrow. 

Daniel. 

b. The other example, using numbers, is as follows: 

JACKSONVILLE, Nov. 17. 

S. PASCO and E. M. L'ENGLE: 


> For a true picture of this cipher, the explanation of which is often distorted beyond recognition even by cryp¬ 
tographers, see Bacon’s own description of it as contained in his De AugmentU ScieTUiarum (.The AdeaneemetU of 
Learning), as translated by any first-class editor, such as Gilbert Watts (1640) or Ellis, Spedding, and Heath 
(1857, 1870). The student is cautioned, however, not to accept as true any alleged “decipherments" obtained 
by the application of Bacon’s cipher to literary works of the 16th century. These readings are purely subjective. 

* In the 16th Century, the letters I and J were used interchangeably, as were also U and V. Bacon’s alphabet 
was called by him a “biliteral alphabet’’ because it employs permutations of two letters. But from the cryptan- 
alytic standpoint the significant point is that each plain-text letter is represented by a 6-character equivalent. 
Hence, present terminology requires that this alphabet be referred to as a quinqueliteral alphabet. 


84 

55 

84 

25 

93 

34 

82 

31 

31 

75 

93 

82 

77 

33 

55 

42 

93 

20 

93 

66 

77 

66 

33 

84 

66 

31 

31 

93 

20 

82 

33 

66 

52 

48 

44 

55 

42 

82 

48. 

89 

42 

93 

31 

82 

66 

75 

31 

93 


_ DANIEL. 

* New York Tribune, Extra No. ii. TTie Cipher Dispatches, New York, 1879. 


148274—38-6 






62 


There were, of course, several messages of like nature, and examination disclosed that 
only 26 different numbers m all were Tised. Solution of these ciphers followed very easily, the 
dedpherment of the one g^ven above being as follows: 

Jacesonvills, Nov. 17. 

S. Pasco and E. M. L’Enqlb; 

Cocke will be ignored, Eagan called in. Authority reliable. 

Daniei.. 

e. The Tribune experts gave the following alphabets as the result of their decipherments: 


AA=0 

EN*Y 

IT=D 

NS=E 

PP=H 

SS=N 

AI=:U 

EP=C 

UA=B 

NY=M 

SH=L 

YE=:F 

EI=I 

IA=K 

MH=G 

PE=T 

SN=P 

YI=X 

EM=V 

lVk=S 

NN=5J 

PI=R 

SP=W 

YY=A 

20=D 

33=N 

44=H 

62=X 

77=G 

89=Y 

25=K 

34=W 

48=T 

66=A 

82=1 

93=E 

27=8 

39=P 

52=U 

68=F 

84=C 

96=M 

31=L 

42>=R 

56=0 

75=B 

87=V 

99=J 


They did not attempt to correlate these alphabets, or at least they say nothing about a possible 
relationship. The present author has, however, reconstructed the rectangle upon which these 
alphabets are based, and it is given below (fig. 16). 


H 1 
I 2 
S 3 
P 4 
A 5 

y 6 

M 7 
E 8 
N 9 


T 0 

riQVBl 16. 

It is amusing to note that the conspirators selected as their key a phrase quite in keeping with 
their attempted illegalities—HIS PAYMENT—for bribery seems to have played a considerable 
part in that campaign. The blank squares in the diagram probably contained proper names, 
numbers, etc. 



2d Letter or Number 



Section VIII 


MULTIUTERAL SUBSTITUTION WITH MULTIPLE-EQUIVALENT CIPHER 
ALPHABETS 


Purpose of providing multiple-equivalent cipher alphabets_ 37 

Solution of a simple example---__ 38 

Solution of more complicated example-*__ 39 

A subterfuge to prevent decomposition of cipher text into component unite_ — 40 


37. Purpose of providing multiple-equivalent cipher alphabets.— a. It has been seen that 
the characteristic frequencies of letters composing normal plain text, the associations they form 
in combining to form words, and the peculiarities certain of them manifest in such text all afford 
direct clues by means of which ordinary monoalphabetic substitution encipherments of such 
plain text may be more or less speedily solved. This has led to the introduction of simple 
methods for disguising or suppressing the manifestations of monoalphabeticity, so far as possible. 
Basically these methods are multiliteral and they will now be presented. 

b. Multiliteral substitution may be of two types: (1) That wherein each letter of the plain 
text is represented by one and only one multiliteral equivalent. For example, in the Francis 
Bacon cipher described in Par. 35e, the letter Kp is invariably represented by the permutation 
abaab. For this reason this type of system may be more completely described as tnonocUpha- 
betic, mvltiliteral subatUviion with single-e^imlent cipher alphabets. 

(2) That wherein, because of the lai^e number of equivalents made available by the com¬ 
binations and permutations of a limited number of elements, each letter of the plain text may be 
represented by several multiliteral equivalents which may be selected at random. For example, 
if 3-letter combinations are employed there are available 26® or 17,576 equivalents for the 26 
letters of the plain text; they may be assigned in equal numbers of different equivalents for the 
26 letters, in which case each letter would be representable by 676 different 3-letter equivalents^ 
or they may be assigned on some other basis, for example, proportionately to the relative 
frequencies of plain-text letters. For this reason this type of system may be more completely 
described as monoalphabetic, mvUiliterdl substitwtion with mvltiple-eguivalent cipher alphabets. 
Some authors term such a system “simple substitution with multiple equivalents”; others term 
it monoalphabetic substitution with variants. For the sake of brevity, the latter designation will 
be employed in this text. 

c. The primary object of monoalphabetic substitution with variants is, as has been men¬ 
tioned above, to provide several values which may be employed at random in a simple substitution 
of cipher equivalents for the plain-text letters. In this connection, reference is made to Section 
X of Elementary Military Cryptography, wherein several of the most common methods for 
producing and using variants are set forth. 

d. A word or two concerning the underlying theory from the cryptanalytic point of view of 
monoalphabetic substitution with variants, may not be amiss. T^ereas in simple or single¬ 
equivalent, monoalphabetic substitution it is seen that— 

(1) The same letter of the plain text is invariably represented by but one and always the 
same character of the cryptogram, and 


( 63 ) 













64 


(2) The same character of the cryptogram invariably represents one and always the same 
letter of the plain text; 

In multiliteral substitution with multiple equivalents (monoalphabetic substitution with 
variants) it is seen that— 

(1) The same letter of the plain text may be represented by one or more different characters 
of the cryptogram, but 

I (2) The same character of the cryptogram nevertheless invariably represents one and always 

[ the same letter of the plain text. 

38. Solution of a simple example.—o. The following cryptogram has been enciphered by a 
! set of four alphabets similar to the following: 

ABCDEFGHI-JKLMN0PQRSTUVWXY2 
08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 01 02 03 04 05 06 07 

35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 26 27 28 29 30 31 32 33 34 

68 69 70 71 72 73 74 75 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 

87 88 89 90 91 92 93 94 95 96 97 98 99 00 76 77 78 79 80 81 82 83 84 85 86 

The keyword here is TRIP*. In enciphering a message the equivalents are to be selected at 
random from among the four variants for each letter. The steps in solving a message produced 
by such a scheme will now be scrutinized. 

Cbtptoqeam 

68321 09022 48057 65111 88648 42036 45235 09144 05764 22684 

- 00225 57003 97357 14074 82524 40768 51058 93074 92188 47264 

I 09328 04255 06186 79882 85144 45886 32574 55136 56019 45722 

f 76844 68350 45219 71649 90528 65106 11886 44044 89669 70553 

i 18491 06985 48579 33684 50957 70612 09795 29148 56109 08546 

- 62062 65509 32800 32568 97216 44282 34031 84989 68564 53789 

12530 77401 68494 38544 11368 87616 56905 20710 58864 67472 

22490 09136 62851 24551 35180 14230 50886 44084 06231 12876 

05579 58980 29503 99713 32720 36433 82689 04516 52263 21175 

06445 72255 68951 86957 76095 67215 53049 08567 9730 

b. Assuming that the foregoing remarks had not been made and that the crypt(^;ram has 
just been submitted for solution with no information concerning it, the first step is to make a 
preliminary study to determine whether the cryptogram involves cipher or code. The crypto¬ 
gram appears in 6-figure groups, which may indicate either cipher or code. A few remarks will 
be made at this point with reference to the method of determining whether a cryptogram com¬ 
posed of figure groups is in code or cipher, using the foregoiog example. 

c. In the first place, if the cryptogram contains an even number of digits, as for example 
494 in the foregoing message, this leaves open the possibility that it may be cipher, composed of 
247 pairs of digits; were the number of digits an exact odd multiple of five, such as 125,135, etc., 
the possibility that the cryptogram is in code of the 5-figure group type must be consider^. Next, 
a preliminary study is made to see if there are many repetitions, and what their characteristics 

i * The letter corresponding to the lowest number in each line of the diagram showing the cipher alphabets 

|j is a key letter. Thus, in the let line Ol^T; in the 2d line 26=R; etc. 


I 


are. If the cryptogram is code of the 5-figur6 group ts^pe, then such repetitions as appear should 
generally be in whole groups of five digits, and they should be visible in the text just as the mes¬ 
sage stands, imless the code message has undergone encipherment also. If the cryptogram is in 
cipher, then the repetitions should extend beyond the 5-digit groupings; if they conform to any 
definite groupings at all they should for the most part contain even numbers of digits since each" 
letter is probably represented by a pair of digits. If no clues of the foregoing nature are present, 
doubts will be dissolved by maldng a detailed study of frequencies. 

d. A simple 4-part frequency distribution is therefore decided upon. Shall the alphabet be 
assumed to be a 25- or a 26-character one? If the former, then the 2-digit pairs from 01 to 00 
fall into exactly four groups each corresponding to an alphabet. Since this is the most common 
scheme of drawing up such alphabets, let it be assumed to be true of the present case. The 
following distributions result from the breaking up of the text into 2-digit pairs. 


01-/// 

26-/// 

51—m 

76—m/ 

02— 

27— 

52—m 

77-1 

03-//// 

28—/ 

63-/// 

78— 

04—/ 

29—/ 

54— 

79—/ 

05~m 

30-/// 

55-1111 

80-/// 

06—/«// 

31— 

56-m 

81— 

07-111 

S2—mi 

57—m/ 

82-////. 

08— 

33—/ 

56-11 

83—/ 

09-//// 

34—/ 

69— 

84—///// 

10-//// 

35-// 

60— 

85—m/ 

11—M 

36—m 

61— 

86-1/1 

12-/// 

37—1 

62-// 

87— 

13—/ 

38— 

63— 

88-//// 

14—/ 

39—/ 

64—/«// 

89—m 

15—/ 

40-111 

65— 

90—m/ 

16-/// 

41— 

66—/ 

91-/// 

17— 

42-//// 

67-// 

92—/ 

18—/«// 

43-1 

68—m H 

93—/ 

19— 

44—mi 

69-1/ 

94—/ 

20—f 

4&-mi 

70—/ 

95-/// 

21-11 

46-111 

71-/ 

96— 

22~m 

47— 

72-//// 

97—m/ 

23-// 

48-/// 

73— 

98—/ 

24— 

40—m 

74^1111 

99— 

25-/ 

50—m 

75-1 

00-// 


e. If the student will bring to bear upon this problem the principles he learned in Section V 
of this text, he will soon realize that what he now has before him are four, simple, monoalpha¬ 
betic frequency distributions si m ilar to those involved in a monoalphabetic substitution cipher 
using standard cipher alphabets. The realization of this fact immediately provides the clue to 
the next step: “fitting each of the distributions to the normal.” (See Par. 176). This can be 





done without difficulty in this case (remembering that a 25-letter alphabet is involved and 
assuming that I and J are the same letter) and the following alphabets result: 


01—w 

26—U 

51—N 

76—E 

02—K 

27—V 

52-0 

77—F 

03—L 

28—W 

53—P 

78—G 

04—M 

29—X 

54—Q 

79—H 

05—N 

30—Y 

55—R 

80—I->J 

06-0 

31—Z 

56—S 

81—K 

07—P 

32—A 

57—T 

82—L 

08—Q 

33—B 

58—U 

83—M 

09—R 

34—C 

59—V 

84—N 

10—S 

35—D 

60—W 

85—0 

11—T 

36—E 

61—X 

86—P 

12—U 

37—F 

62—Y 

87—Q 

13—V 

3B—G 

63—Z 

88—R 

14—W 

39—H 

64—A 

89—S 

15—X 

40—W 

65—B 

90—T 

16—Y 

41—K 

66—C 

91—U 

17—Z 

42—L 

67—D 

92—V 

18—A 

43—M 

68—E 

93—W 

19—B 

44—N 

69—F 

94—X 

20—C 

45—0 

70—G 

95—Y 

21—D 

46—P 

71—H 

96—Z 

22—E 

47—Q 

72—I-J 

97—A 

23—F 

48—R 

73—K 

98—B 

24—G 

49—S 

74—L 

99—C 

25—H 

50—T 

75—M 

00—D 


/. The keyword is seen to be JUNE and the first few groups of the cryptogram decipher as 
follows: 

68 32 10 90 22 48 05 76 51 11 88 64 84 20 36 45 23 

EAST .ERNENTRANCEOF 
g. From the detailed procedme given above, the student should be able to draw his own 
conclusions as to the procedure to be followed in solving cryptograms produced by methods 
which are more or less simple variations of that just discussed. In this connection he is referred 
to Section X of Elementary Military Cryptography, wherein a few of these variations are mentioned. 

A. Possibly the most important of the variations is that in which a rectangle such as that 
shown in Fig. 17 is employed. 



1 

2 

3 

4 

5 

6 

7 

8 

9 

0 

1, 4, 7 

A 

B 

C 

D 

E 

F 

G 

H 

I 

J 

2, 5, 8 

K 

L 

M 

-LI 

0 

P 

Q 

R 

S 

T 

3, 6. 9 

U 

V 

W 

X 

Zj 

Z 

- 





I 

I 


i 


In the solution of cases of ibis kind, repetitions would play their usual role, with the modifications 
noted below in Par. 39. Once an entering wedge has been forced, through the identification 
of one or more repeated words such as BATTALION, DIVISION, etc., the entire enciphering 
rectangle would soon be reconstructed. It may be added that the frequency distribution for 
the text of a single long message or several short ones enciphered by such a system would show 
characteristic phenomena, the most important of which are, first, that the distribution for a 
rectangle such as shown in Fig. 17 would practically follow the normal and, second, that the 
distribution for the 2d digit of pairs would show more marked crests and troughs than the 
distribution for the 1st digit. For example, the initial digits 1, 4, and 7 (for the numbers 10-19, 
40-49, and 70-79, inclusive) would apply to the distribution for the letters A to J, inclusive; the 
initial digits 2, 5, and 8 would apply to the distribution for the letters K to T, inclusive. The 
total weighted frequency values for these two groups of letters are about equal. Therefore, 
the frequencies of the initial digits 1, 2, 4, 6, 7, and 8 would be approximately equal. But 
consider the final digit 5 in the numbers 15, 45, 75, 25, 55, and 85; its total frequency is com¬ 
posed of the frequency of Ep plus the frequency of Op; whereas in the case of the final digit 6, 
its total frequency is composed of the frequency of Fp plus the frequency of Qp. The two cases 
would show a marked difference in frequency. Of course, the letters may be inserted within 
the enciphering rectangle in a keyword-mixed or even in a random order; the numbers may be 
applied to the rectangle in a random order. But these variations, while increasing the difficulty 
in solution, by no means make the latter as great as may be thought by the novice. 

39. Solution of a more complicated example.— a. As soon as a beginner in cryptography 
realizes the consequences of the fact that letters are used with greatly varying frequencies 
in normal plain text, a brilliant idea very speedily comes to him. Why not disguise the 
natural frequencies of letters by a system of substitution using many equivalents, and let 
the numbers of equivalents assigned to the various letters be more or less in direct proportion 
to the normal frequencies of the letters? Let E, for example, have 13 or more equivalents; T, 10; 
N, 9; etc., and thus (he thinks) the enemy cryptanalyst can have nothing in the way of tell-tale 
or characteristic frequencies to use as an entering wedge. 

b. If the text available for study is small in amoimt and if the variant values are wholly 
independent of one another, the problem can become exceedingly diffictilt. But in practical 
military communications such methods are rarely encountered, because the volume of text is usually 
great enough to permit of the establishment of equivalent values. To illustrate what is meant, 
suppose a set of cryptograms produced by the monoalphabetic-variant method described above 
shows the following two sets of groupings in the text: 

Set a Set B 


12-37-02-79-68-13-03-37-77 

82-69-03-79-13-68-23-37-35 

82-69-51-16-13-13-78-05-35 

91-05-02-01-68-^2-78-37-77 


71-12-02-51-23-05-77 

11-82-51-02-03-05-35 

11-91-02-02-23-37-35 

97-12-51-03-78-69-77 


An examination of these groupings would lead to the following tentative conclusions with regard 
to probable equivalents: 

12, 82, 91 01, 16, 79 03, 23, 78 

05,37,69 13,42,68 35, and 77 

02, and 51 

The establishment of these equivalencies would sooner or later lead to the finding of additional 
sets of equal values. The completeness with which this can be accomplished will determine 







68 

the ease or diflSculty of solution. Of course, if many equivalendes can be established the 
problem can then be reduced practically to monoalphabetic terms and a speedy solution can 
be attained. 

c. Theoretically, the determination of equivalencies may seem to be quite an easy matter, 
but practically it may be very difficult, because the cryptanalyst can never be certain that a 
combination showing what may appear to be a variant value is really such, and is not a different 
word. For example, take the groups— 

17-82-31-82-14-63, and 
27-82-40-82-14-63 

Here one might suspect that 17 and 27 represent the same letter, 31 and 40 another letter. But 
it happens that one group represents the word MANAGE, the other DAMAGE. 

d. When reversible combinations are used as variants, the problem is perhaps a bit more 
simple. For example, using the accompanying Fig. 18 for encipherment, two messages vdth 
the same initial words, REFERENCE YOUR, may be enciphered as follows: 


K,Z Q,V B,H M,R D.L 



REFER ENCEY OUR 

(1) N H W D R X L S H C D W W Z N R S L H P S R B J C H 

(2) CHDWR XSLHN DWZWN RLSHP RWJBN H 

The experienced Cryptanalyst, noting the appearance of the very first few groups, assumes that 
he is here confronted with a case involving biliteral reversible equivalents, with variants. 

e. The probable-word method of solution may he used, but with a slight variation intro¬ 
duced by virtue of the fact that, regardless of the system, leUers oj low frequency in plain text 
remain injrequent. Hence, suppose a word containing low-frequency letters, but in itself a 
rather common word strikingly idiomorphic in character is sought as a “probable word”; for 
example, words such as CAVALRY, ATTACK, and PREPARE. Writing such a word on a slip of 
paper, it is slid one interval at a time under the text, which has been marked so that the high 
and low-frequency characters are indicated. Each coincidence of a low-frequency letter of the 
text with a low-frequency letter of the assumed word is examined carefully to see whether the 
adjacent text letters correspond in frequency with the other letters of the assumed word; or, if 
the latter presents repetitions, whether there are correspondences between repetitions in the 
text and those in the word. Many trials are necessary but this method will produce results 
when the difficulties are otherwise too much for the cryptanalyst to overcome. 

40. A subterfuge to prevent decomposition of cipher text into component units.— a. A few 
words should be added with regard to certain subterfuges which are sometimes encountered in 
monoalphabetic substitution with variants, and which, if not recognized in time, cause con¬ 
siderable delays. These have to deal with the insertion of nulls so as to prevent the cryptanalyst 
from breaking up the text into its real cryptographic units. The student should take careful 



note of the last phrase; the mere insertion of symbols having the same characteristics as the 
symbols of the cryptographic text, except that they have no meaning, is not what is meant. 
This class of nulls rarely achieves the purpose for which they are intended. What is really meant 
can best be explained in connection with an example. Suppose that a 5 x 5 checkerboard design 
with the row and column indicators shown in Fig. 19 is adopted for encipherment. Normally, 
the cipher units would consist of 2-letter combinations of the indicators, invariably giving the 
row indicator first (by agreement). 

V G I W D 

A H P S M 

T 0 E B N 

F U R L C 



The phrase COMMANDER OF SPECIAL TROOPS might be enciphered thus: 

COMMANDEROF... 

VI EB PH lU FT IE AB TM WO PW GT ... 

These would normally then be arranged in 5-letter groups, thus: 

VIEBP HIUFT lEABT MWOPW GT... 

h. It will be noted, however, that only 20 of the 26 letters of the alphabet have been employed 
as row and column indicators, leaving J, K, Q, X, Y, and Z unused. Now, suppose these five letters 
are used as nulls, not in pairs, hvi as individual letters inserted at random just before the real text is 
arranged in 5-letter groups. Occasionally, a pair of nulls is inserted. Thus, for example: 

VIEXB PHKIU FJXTI EAJBT MWOQP WGKTY 
The cryptanalyst, after some study, suspecting a biliteral cipher, proceeds to break up the text 
into pairs: 

VI EX BP HK lU FJ XT IE AJ BT MW OQ PW GK TY 
Compare this set of 2-letter combinations with the correct set. Only 4 of the 15 pairs are “proper” 
units. It is easy to see that without a knowledge of the existence of the nulls, and even with a 
knowledge, if he does not know which letters are nulls, the cryptanalyst would be confronted with 
a problem for the solution of which a fairly large amount of text might be necessary. The 
careful employment of the variants also very materially adds to the security of the me^od be¬ 
cause repetitions can be rather effectively suppressed. 

c. From the cryptographic standpoint, the fact that in this system the cryptographic text 
is more than twice as long as the plain text constitutes a serious disadvantage. Erom the 
cryptanalytic standpoint, the masking of the cipher units constitutes the most important source 
of strength of the system; this, coupled with the use of variants, makes it a bit more difficult 
system to solve, despite its monoalphabeticity. 





71 


Section IX 

POLYGRAPHIC SUBSTITUTION SYSTEMS 

Pangisph 


Monographic and polygraphic substitution systems_ 41 

Tests for identifying digraphio substitution_ 42 

General procedure in the analysis of digraphic substitution ciphers_ 43 

Analysis of digraphio substitution ciphers based upon 4-equare checkerboard designs_ 44 

Analysis of ciphers based upon other types of checkerboard designs_ 46 

Analysis of the Playfair cipher system_ 46 


41. Monographic and polygraphic snhstitution systems.— a. The student is now referred 
to Sections VII and VIII of Advanced Military Cryptography, wherein polygraphic systems of 
substitution are discussed from the cryptographic point of view. These will now be discussed 
from the cryptanalytic point of view. 

b. Although the essential differences between polyliteral and polygraphic substitution are 
treated with some detail in Section VII of Advanced Military Cryptography, a few additional 
words on the subject may not be,amiss at this point. 

c. The two primary divisions of substitution systems into (1) uniliteral and multiliteral 
methods and into (2) monographic and poly^aphfc methods are both based upon considerations 
as to the number oj elemmis constituting.the plauv-text imd the equivalent cipher-text units. In 
uniliteral as well as in monographic substitution, each plain-text unit consists of a ain glA element 
and each cipher-text unit consists of a single element. The two terms uniliteral and mono¬ 
graphic are therefore identical in significance, as defined cryptographically. It is when the 
terms multiliteral and polygraphic are examined that an essential difference is seen. In multi- 
literal substitution the plain-text unit always consists of a single element (one letter) and the 
cipher-text unit consists of a group of two or more elements; when biliteral, it is a pair of elements, 
when triliteral, it is a set of three elements, and so on. In what wOl herein be designated as 
true or complete polygraphic substitution the plain-text unit consists of two or more elements 
forming an indivisible compound; the cipher-text unit usually consists of a corresponding number 
of elements.' When the number of elements comprising the plain-text units is fixed and always 
two, the system is digraphic; when it is three, the system is trigraphic; when it is four, tetra- 
graphic; and so on.® It is important to note fiat in true or complete polygraphic substitution 
the elements combine to form indivisible compounds having properties different from those of 
either of the constituent letters. For example, in uniliteral substitution ABp may yield XY# and 
ACp may yield XZ*; but in true digraphic substitution ABp may yield XYo and ACp may yield 

A difference in identify of one letter affects the whole result.® An analogy is found in chemistry, 
when two elements combine to form a molecule, the latter usually having properties quite 
different from those of either of the constituent elements. For example: sodium, a metal, and 

> The qualifying adverb “usually” is employed because this correspondence is not essential. For example, 
if one should draw up a set of 676 arbitrary single signs, it would be possible to represent the 2-letter pairs from 
AA to ZZ by single symbols. This would still be a digraphic system. 

* In this sense a code system is merely a polygraphic substitution system in which the number of elements 
constituting the plain-text units is variable. 

• For this reason the two letters are marked by a ligature, that is, by a bar across their tops. 

(70) 


chlorine, a gas, combine to form sodium chloride^ common table salt. Furthermore, sodium and 
fluorine, also a gas similar in many respects to chlorine, combine to form sodium fluoride, which 
is much different from table salt. Partial and pseudo-polygraphic substitution will be treated 
under subparagraphs d and e below. 

d. Another way of looking at polygraphic substitution is to regard the elements comprising 
the plain-text units as being enciphered individually and polyalphabetically by a fairly large 
number of separate alphabets. For example, in a di^aphic system in which 676 pairs of plain¬ 
text letters are representable by 676 cipher-text pairs assigned at random, this is equivalent to 
having a set of 26 different alphabets for enciphering one member of the pairs, and another set 
of 26 different alphabets for enciphering the other member of the pairs. According to this 
viewpoint the different alphabets are brought into play by the particular combination of letters 
forming each plain-text pair. This is, of course, quite different from systems wherein the various 
alphabets are brought into play by more definite rules; it is perhaps this very absence of definite 
rules guiding the selection of alphabets which constitutes the cryptographic strength of this type 
of polygraphic system. 

e. When regarded in the light of the preceding remarks, certain systems which at first glance 
seem to be polygraphic, in that groupings of plain-text letters are treated as units, on closer 
inspection are seen to be only partially polygraphic, or pseudo-polygraphic in character. For 
example, in a system in which encipherment is by pairs and yet one of the letters in each pair is 
enciphered monoalphabeticaily, the other letter, polyalphabetically, the method is only psuedo- 
polygraphic. Cases of this type are shown in Section VII of Advanced Military Cryptography. 
Again, in a system in which encipherment is by pairs and the encipherments of the left-hand 
and right-hand members of the pairs show group relationships, this is not pseudo-polygraphic 
but only partially polygraphic. Cases of this type are also shown in the text r^erred to above. 

/. The fundamental purpose of polygrapMc substitution is again the suppression of the 
frequency characteristics of plain text, just as is the case in monoalphabetic substitution with 
variants; but here this is accomplished by a different method, the latter arising from a somewhat 
different approach to the problem involved in producing cryptographic security. When the sub¬ 
stitution involves replacement of single letters in a monoalphabetic system, the cryptogram can 
be solved rather readily. Basically the reason for this is that the principles of frequency and the 
laws of probability, applied to individual units of the text (single letters), have a very good 
opportunity to manifest themselves. A given volume of text of say n plain-text letters, enciphered 
piu^ly monoalphabeticaily, affords n cipher characters, and the same number of cipher units. 
The same volume of text, enciphered digraphicaUy, still affords n cipher characters but only 
2 cipher units. Statistically speaking, the sample within which the laws of probability now apply 
has been cut in half. Furthermore, from the point of view of frequency, the veiy noticeable 
diversity in the frequencies of individual letters, leading to the marked crests and troughs of 
the uniliteral frequency distribution, is no longer so strikingly in evidence in the frequencies of 
digraphs. Therefore, although true digraphic encipherment, for example, cuts the cryptographic 
textual units in half, the dfficulty of solution is not doubled, but, if a matter of judgment arising 
from practical experience can be expressed or approximated mathematically, squared or cubed. 

g. Sections VII and VIII of Advanced Military Cryptography show various methods for the 
derivation of polygraphic equivalents and for handling these equivalents in cryptographing and 
decryptographing messages. The most practicable of those methods are digraphic in character 
and for this reason their solution will be treated in a somewhat more detailed manner than will 
trigraphic methods. The latter can be passed over with the simple statement that their analysis 
requires much text to permit of solution by the frequency method, and hard labor. Fortunately, 
they are infrequently encountered because they are diflGlcult to manipulate without extensive 













72 

tables/ If the latter are required they must be compiled in the form of a book or pamphlet. If 
one is w illing to go that far, one might as well include in such document more or less extensive lists 
of words and phrases, in which case the system falls under the category of code and not cipher. 

42. Tests for identifying digraphic substitution.— a. The testa which are applied to deter¬ 
mine whether a given cryptogram is digraphic in character are usually rather simple. If there 
are many repetitions in the cryptogram and yet the uniliteral-frequenoy distribution gives no 
clear-cut indications of monoalphabeticity; if most of the repetitions contain an even number 
of letters; and if the cryptogram contains an even number of letters, it may be assumed to be 
digraphic in nature. 

h. The student should first try to determine whether the substitution is completely digraphic, 
or only partially digraphic, or pseudo-digraphic in character. As mentioned above, there are 
cases in which, although the substitution is effected by taking pairs of letters, one of the members 
of the pairs is enciphered monoalphabetically, the other member, polyalphabeticaUy. A dis¬ 
tribution based upon the letters in the odd positions and one based upon those in the even 
positions should be made. If one of these is clearly monoalphabetic, then this is evidence that the 
message represents a case of pseudo-digraphism of the type here described. By attacking the 
monoalphabetic portion of the messages, solution can soon be reached by slight variation of the 
usual method, the polyalphabetic portion being solved by the aid of the context and considera¬ 
tions based upon the probable nature of the substitution chart. (See Tables 2, 3, and 4 of 
Adoaneed Military Cryptography,) It will be noted that the charts referred to show definite 
symmetry in their construction. 

e. On the other hand, if the foregoing steps prove fruitless, it may be assumed that the 
cryptogram is completely digraphic in character. 

d. Just as certain statistical tests may be applied to a cryptogram to establish its mono¬ 
alphabeticity, so also may a statistical test be applied to a cryptogram for the purpose of estab¬ 
lishing its d^aphicity. The nature of this test and its method of application will be discussed 
in a subsequent text. 

43. General procedure in the analysis of digraphic substitution ciphers.— a. The analysis of 
cryptcgrams which have been produced by digraphic substitution is accomplished largely by 
the application of the simple principles of frequency of digraphs, with the additional aid of such 
special circumstances as may be known to or suspected by the cryptanalyst. The latter refer 
to peculiarities which may be the result of the particular method employed in obtaining the 
equivalents of the plain-text digraphs in the cryptographing process. In general, however^ 
only if there is sufficient text to disclose the normal phenomena of repetition will solution be 
feasible or possible. 

6. However, when a digraphic system is employed in regular service, there is little doubt 
but that traffic will rapidly accumulate to an amount more than sufficient to permit of solution 
by simple principles of frequency. Sometimes only two or three long messages, or a half dozen 
of average length are sufficient. For with the identification of only a few cipher digraphs, 
larger portions of messages may be read because the skeletons of words formed from the few 
high-frequency digraphs very definitely limit the values that can be inserted for the intervening 
unidentified digraphs. For example, suppose that the plain-text digraphs TH, ER, IN, IS, OF, 
NT, and TO have been identified by frequency considerations, corroborated by a tentatively 
identified long repetition; and suppose also that the enemy is known to be using a quadricular 

* A patent has been granted upon a rather Ingenious machine for automatically accomplishing true poly- 
graphic substitution, but it has not been placed upon the market. See U. S. Patent No. 1845947 issued in 1932 
to Weisner and Hill. In U. 8. Patent No. 1515680 issued to Henkels in 1924, there is described a mechanism 
which also produces polygraphic substitution. 


73 

table of 676 cells containing digraphs showing reciprocal equivalence between plain and cipher- 
text digraphs. Suppose the message begins as follows (in which the assumed values have been 
inserted): 

XQ VO ZI LK AP OL ZX PV QN IK OL UK AL HN LK VL 

FO TH IN NT RE NT NO IN 

BN OZ KU DY EL LE YW 

SI ON TO 

The words FOURTH INFANTRY REGIMENT are readily recognized. The reciprocal pairs EL# 
and LEb suggest ATTACK. The beginning of the message is now completely disclosed: FOURTH 
INFANTRY REGIMENT NOT YET IN POSITION TO ATTACK. The values more or less automati- 
caUy determined are V0 b=URp, AL„=TYp, HN.=ETp, VLb=P0p, 0Zb=TIp, YWe=CKp. 

e. Once a good start has been made and a few words have been solved, subsequent work 
is quite simple and straightforward. A knowledge of enemy correspondence, including data 
regarding its most common words and phrases, is of great assistance in breaking down new 
digraphic tables of the same nature but with different equivalents. 

d. The foregoing remarks also apply to the details of solution in cases of partially 
digraphic substitution. 

44. Analysis of digraphic substitution ciphers based upon 4-square checkerboard designs.— 
a. In Section VIII of Advanced Military Cryptography there are shown various examples of di¬ 
graphic substitution based upon the use of checkerboard designs. These may be considered 
cases of partially digraphic substitution, in that in the checkerboard system there are certain 
relationsffips between plain-text digraphs having common elements and their corresponding 
cipher-text digraphs, which will also have common elements. For example, take the following 
4-square checkerboard design: 


B 

ff 

G 

R 

M 

0 

P 

A 

U 

L 

N 

Y 

V 

X 

E 

H 

Z 

Q 

D 

F 

S 

I 

C 

T 

K 

K 

I 

T 

S 

C 

U 

P 

L 

A 

0 

M 

W 

R 

B 

G 

D 

Z 

F 

Q 

H 

E 

Y 

X 

N 

V 

W 

A 

L 

E 

S 

C 

X 

K 

P 

B 

F 

H 

U 

I 

T 

0 

M 

Y 

D 

V 

P 

X 

B 

K 

C 

s 

A 

E 

w 

L 

N 

Z 

R 

Q 

G 

G 

Z 

Q 

N 

R 

D 

M 

V 

Y 

0 

T 

H 

I 

F 

U 


notmiSO. 


Here BCp=0ffo, B0p=0Fe, BSp==0Pe, BGp=0N, and BTp=0Dc. In each case when Bp is the initial 
letter of the plain-text pair, the initial letter of the cipher-text equivalent is 0#. This, of course, 
b the direct result of the method; it means that the encipherment b monoalphabetic for the 








74 


first half of each of these plain-text pairs, polyalphabetic for the second half. This relation¬ 
ship holds true iov four other groups of pairs beginning with Bp. In other words, there are five 
alphabets employed, not 25. Thus, this case differs from the case discussed under Par. 42i 
only in that the monoalphabeticity is not complete for one-half of all the pairs, but only among 
the members of certain groups of pairs. In a completely digraphic system using a 676-cell 
randomized square, such relationships are entirely absent and for this reason the system is 
cryptographically more secure than the checkerboard system. 

h. From the foregoing, it is clear that when solution has progressed sufficiently to disclose 
a few values, the insertion of letters within the cells of the checkerboard design to give the plain¬ 
text and cipher relationships indicated by the solved values immediately leads to the disclosure 
of additional values. Thus, the solution of only a few values soons leads to the breakdown of 
the entire checkerboard des^. 

c. (1) The following example will serve to illustrate the procedure. Let the message be as 
foUows: 

1 2 3 4 5 5 7 8 9 10 11 12 13 14 15 15 17 18 19 20 21 22 23 34 25 35 27 28 29 30 

A. HFCAP GOQIL B S P K M NDUKE OHQNF BORUN 

B. QCLCH QBQ B F H M AFX SIOKO QYFNS XMCGY 

C. XIFBE X AFDX LPMXH HRGKG Q. K Q M L F E Q Q I . 

- D. G 0 I H M UEORD CLTU F EQQ CG QNHF X IFBEX 

E. FLBUQ FCHQO QMAFT XSYCB EPF N B S P K N U 

F. Q I T X E U QMLF EQQIG 0 1 EUE HPIAN YTFLB 

G. FEEPI DHPCG NQIH B F H M HF XCKUP DGQPN 


H. CBCQL QPNFN PNITO RTENC 

I. ^ZLQCI AAIQU CHTP C B I F G W 

J. OYCRQ QDPRX FN 0 M L F I D G C 

K. IRCGG GNDLN OZTFG EERRP 


0 B C N T F H H A Y 
KFCQS LQMCB 
C G I 0 G 0 I H H F 
I F H 0 T F H H A Y 


(2) The cipher having been tested for standard alphabets (by the method of completing 
the normal components) and found to give negative results, a uniliteral-frequency distribution 
is made. It is as follows: 


- g g 

g g ^ g g 

g ..g^^gg 5 -.g 

^gg ggggg g-,gggg =5 

ggg^ggggg 5 g g g g g g g g g g 5- 

ggggggggg ggggg g ggggg ..gg^ 

ABCDEFGHIJKLMNOPQRSTUVWXYZ 

11 15 20 8 15 30 17 22 24 0 8 14 11 18 15 15 33 9 5 11 11 0 1 12 7 3 

FloUEi 21. 


(3) At first glance this may appear to the untrained eye to be a monoalphabetic frequency 
distribution but upon closer inspection it is noted that aside from the frequencies of four or five 


75 


letters the frequencies for the remaining letters are not very dissimilar. There are, in reality, no 
very marked crests and troughs, certainly not as many as would be expected in a monoalphabetic 
substitution cipher of equal length. 

(4) The message having been carefuUy examined for repetitions of 4 or more letters, all of 
them are listed: 



Frequency 

Located in lines 

TFHHAYZLQCIAAIQUCHTP (20 letters) . 

2 

H and K. 

QMLFEQQIGOI (11 letters). 

2 

C and F. 

XIFBEX (6 letters). 

2 

C and D. 

FEQQ... 

3 

C, D, F. 

QMLF...- 

3 

C, F, J. 

BFHM.. 

2 

B and G. 

BSPK. 

2 

A and E. 

GOIH... 

2 

D and J. 


Since there are quite a few repetitions, two of considerable length, since all but one of them 
contain an even number of letters, and since the message also contains an even number of letters, 
344, digraphic substitution is suspected. The cryptogram is transcribed in 2-letter groups, for 
greater convenience in study. It is as follows: 

Message transcribed in pairs 

1 2 3 4 5 5 7 8 9 10 11 12 13 14 15 

A. HF CA PG OQ IL BS PK MN DU KE OH QN FB OR UN 

B. QC LC HQ BQ BF HM AF XS 10 KO QY FN SX MC GY 

C. XI FB EX AF DX LP MX HH RG KG QK QM LF EQ QI 

I>. GO IH MU EO RD CL TU FE QQ CG QN HF XI FB EX 

E. FL BU QF CH QO QM AF TX SY CB EP FN BS PK NU 

F. QI TX EU QM LF EQ QI GO I E UE HP lA NY TF LB 

G. FE EP ID HP CG NQ IH BF HM HF XC KU PD GQ PN 

H. CB CQ LQ PN FN PN IT OR TE NC CB CN TF HH AY 

J. ZL QC lA AI QU CH T P CB IF GW KF CQ SL QM CB 

K. OY CR QQ DP RX FN QM LF ID GC CG 10 GO IH HF 

L. IR CG GG ND LN OZ TF GE ER RP IF HO TF HH AY 

M. ZL QC lA AI QU CH TP 

It is noted that all the repetitions listed above break up properly mto digraphs except m 
one case, viz, FEQQ in lines C, D, and F. This seems rather strange, and at first thought one 
might suppose that a letter was dropped out or was added in the vicinity of the FEQQ in line D. 
But it is immediately seen that the FE QQ in line D has no relation at all to the . F EQ Q. in 
fines C and F, and that the F EQ Q in fine D is merely an accidental repetition. 












76 


77 


(5) A digraphic frequency distribution * is made and is shown in Fig. 22. 



FIOVBI 22. 


(6) The appearance of the foregoing distribution for this message is quite characteristic of 
that for a digraphic substitution cipher. There are many blank cells; although there are many 
cases in which a digraph appears only once, there are quite a few in which a digraph appears 
two or three times, four cases in which a digraph appears four times, and two cases in which a 
digraph appears five times. The absence of the letter J is also noted; this is often the case in a 
digraphic system based upon a checkerboard design, 

• The distinction between “digraphic” and “biliteral” is based upon the following consideration. In a 
biliteral (or diliteral) distribution every two successive letters of the text would be grouped together to form a 
pair. For example, a biliteral distribution of ABCDEF would tabulate the pairs AB, BC, CD, DE, and EF. In a 
digraphio distribution only successive pairs of the text are tabulated. For example, ABCDEF would yield only 
AB, CD, and EF. 


(7) In another common type of checkerboard system known as the Playfair cipher, described 
in Par. 46, one of the telltale indications besides the absence of the letter J is the absence of double 
letters, that is, two successive identical letters. The occurrence of the double letters GG, HH, 
and QQ in the message under investigation eliminates the possibility of its being a Playfair 
cipher. The simplest thing to assume is that a 4-square checkerboard is involved. One with 
normal alphabets in Sections 1 and 2 is therefore set down (Fig. 23a). 


A 

B 

C 

D 

E 






F 

G 

H 

I-J 

K 






L 

M 

N 

0 

P 






Q 

R 

S 

T 

U 






V 

W 

X 

Y 

Z 











A 

B 

"c" 

D 

E 






F 

G 

H 

I-J 

K 






L 

M 

N 

0 

P 


_1 




'V 

R 

~S~ 

T 

U 






V 

W 

X 

Y 

Z 


(8) The recurrence of the group (JMLF, three times, and at intervals suggesting that it might 
be a sentence separator, leads to the assumption that it is the word STOP. The letters Q, M, 
and F are therefore inserted in the appropriate cells in Sections 3 and 4 of the diagram. Thus 
(Fig. 236): 


A 

B 

C 

D 

E 






F 

G 

H 

I-J 

K 






L 

M 

N 

0 

P 





L 

Q 

R 

S 

T 

U 




Q 


V 

W 

X 

Y 

Z 











A 

B 

c 

D 

E 






F 

G 

H 

I-J 

K 




F 


L 

M 

N 

0 

P 



M 



Q 

R 

S 

T 

U 



1 



V 

W 

X 

Y 

Z 


148274—38-6 


Fiqcbi 23b . 


A 



























78 


These placem^ts seem logical. Moreover, in Section 3 the number of cells between L and 
Q is just one less than enough to contain all the letters U to P, inclusive, and suggests that either 
N or 0 is in the kesrword portion of the sequence, that is, near the top of Section 3. Without 
luftking a commitment in the matter, suppose both N and 0, for the present, be inserted in the 
cdl between 11 and P. Thus (Mg. 23c): 


A 

B 

C 

D 

E 






F 

G 

H 

I-J 

K 






L 

M 

N 

0 

P 





L 

Q 

R 

S 

T 

U 

M 

8 

P 

Q 


V 

W 

X 

Y 

Z 











A 

B 

C 

D 

jT 






F 

G 

H 

I-J 

K 




F 


L 

U 

N 

0 

P 



M 



"o’ 

R 

S 

T 

U 






V 

W 

X 

Y 

Z 


riouBi23<. 


(9) Now, if the placement of P in Section 3 is correct, the cipher equivalent of THp will be 
P9,, and there should be a group of adequate frequency to correspond. Noting that PN« occiirs 
three times, it is assumed to be THp and the letter N is inserted in the appropriate cell in Section 4. 
Thus (Mg. 23<i): 





79 


(10) It is about time to try out these assumed values in the message. The proper insertaons 
are made, with the following results: 



1 

2 

2 

4 

s 

s 

7 

8 

9 

10 

11 

u 

13 

14 

u 

A. 

HF 

CA 

PG 

OQ 

IL 

BS„ 

_PK 

HN 

DU 

KE 

OH 

QN 

FB 

OR 

UN 

B. 

QC 

LC 

HQ 

BQ 

BF 

HM 

AF 

XS 

10 

KO 

QY 

FN 

SX 

MC 

GY 

c. 

U- 

FP 


AF 

DX 

LP 

MX 

HH 

RG 

KG 

QK 



_Ea_ 














ST 

OP 



D. 

M= 

_IH 

MU 

EO 

RD 

CL 

TU 

FE 

QQ 

CG 

QN 

HF 

XI 

FB 

EX 

E. 

FL 

BU 

QF 

CH 

QO 

QM 

AF 

TX 

SY 

CB 

EP 

FN 

BS 

PK 

NU 







ST 










F. 

QI 

TX 

EU 


_LF_ 

EQ 


_SQ_ 

IE 

UE 

HP 

lA 

NY 

TF 

LB 





ST 

OP 











G. 

FE 

EP 

ID 

HP 

CG 

NQ 

IH 

BF 

HM 

HF 

XC 

KU 

PD 

GQ 

PN 
















TH 

H. 

CB 

CQ 

LQ 

PN 

FN 

PN 

IT 

OR 

TE 

NC 

CB 

CN 

TF 

HH 

AY, 





TH 


TH 










J. 

,ZL 

jac_ 

lA 

AI 

-91L 

CH 

TP 

CB 

IF 

GW 

KF 

CQ 

SL 

QM 

CB 


K. 

OY 

CR 

QQ 

DP 

RX 

FN 

OM LF 

ID 

GC 

CG 

10 

G0_ 

ST 

IH 

L. 

IR 

CG 

GG 

ND 

LN 

OZ 

ST OP 

TF GE 

ER 

RP 

IF 

HO 

TF 

HH 

M. 

,ZL 

_flC_ 

lA 

AI 


CH 

TP 








(11) So far no impossible combinations are in evidence. Beginning with group H4 in the 
message is seen the following sequence: 

P N F N P N 
T H . . T H 

Aganmfl it to be THAT THE. Then ATp=FNe, and the letter N is to be inserted in row 4 column 1. 
But this is inconsistent with previous assumptions, since N in Section 4 has already been tenta¬ 
tively placed in row 2 column 4 of Section 4. Other assumptions for FN^ are made: that it is, 
ISp (THIS TH...); that it is ENp (THEN TH...); but the same incon^tency is apparent. In fact 
the student will see that FN, must represent a digraph ending in F, G, H, I-rJ, or K, since N, is 
tentatively located on the same line as these letters in Section 2. Now FNo occurs 4 times in 
the message. The digraph it represents rrnist be one of the following: 

DF, DG, DH, DI, DJ, DK 
IF. TG, IH, II, IJ. IK 
JF, JG, JH, JI, JJ, JK 
OF, OG, OH, 01, OJ, OK 
TK, 

YF, YG, YH, YI. YJ, YK 






80 


81 


Of these the only one likely to be repeated 4 times is OF, yielding T H 0 F T H which may be 

P N F N P N 

a part of 

• NORTHOFTHE. .SOUTHOFTHE. 

CQLQPNFNPNIT CQLQPNFNPNIT 

In either case, the position of the F in Section 3 is excellent: F . . . L in row 3. There are 3 
cells intervening between F and L, into which G, H, I-J, and K may be inserted. It is not nearly 
so likely that G, H, and K are in the keyword as that I should be in it. Let it be assumed that 
this is the case, and let the letters be placed in the appropriate cells in Section 3. Thus (Fig. 23c): 


A 

B 

C 

D 

E 






F 

G 

H 

Il-J 

K 






L 

M 

N 

0 

P 

F 

G 

H 

K 

L 

Q 

R 

S 

T 

U 

U 

0 

P 

Q 


V 

W 

X 

Y 

Z 











A 

B 

C 

D 

E 




N 


F 

G 

H 

W 

K 




F 


L 

u 

N 

0 

P 



u 

Q 


T 

R 

S 

T 

U 




!_ 


V 

W 

X 

Y 

Z 


Fiawa 23<. 


Let the resultant derived values be checked against the frequency distribution. If the position of 
H in Section 3 is correct, then the digraph ONp, normally of high frequency should be represented 
several times by HF#. Reference to Fig. 22 shows a frequency of 4 times. And HM,, with 2 occim- 
rences, represents NSp. There is no need to go through all the possible corroborations. 


(12) Going back to the assumption that T H . . T H 
PNFNPN 

is part of the expression 

.NORTHOFTHE. .SOUTHOFTHE.. 

CQLQPNFNPNIT CQLQPNFNPNIT 


it is seen at once from Fig. 23e that the latter is apparently correct and not the former, because 
LQc equals OUp and not ORp. If eSp=CQ„ this means that the letter C of the digraph CQ, must be 
placed in row 1 column 3 or row 2 column 3 of Section 3. Now the digraph CB* occurs 5 times, 
CGe, 4 times, CH„ 3 times, CQo, 2 times. Let an attempt be made to deduce the exact position of 
C in Section 3 and the positions of B, G, and H in Section 4. Since F is already placed in Section 


! 

i 

I 


4, assume G and H directly follow it, and that B comes before it. How much before? Suppose a 
trial be made. Thus (Fig. 23/): 


A 

B 

C 

D 

E 



C 



F 

G 

H 

I-J 

K 



c 



.L 

H 

N 

0 

P 

F 

G 

H 

K 

L 

Q 

R 

S 

T 

U 

M 

B 

P 

Q 


V 

W 

X 

Y 

Z 











A 

B 

_^i 

D 

E 




N 


F 

G 

H 

W 

K 

B 

B 

B 

F 

G 

L 

M 

IT 


P 

H 


M 

"o’ 


V 

R 

s 


IT 






V 

W 

'x * 

_! 

~r 

Z 


Fiauit 23/. 


By referring now to the frequency distribution. Fig. 22, after a very few minutes of experimenta¬ 
tion it becomes apparent that the following is correct: 


A 

B 

C 


E 



c 



F 

G 

H 

I-J 

K 






L 

M 

N 

0 

P 

F 

G 

H 

K 

L 

Q 

R 

S 

T 

U 

M 

8 

P 

Q 


V 

W 

X 

Y 

Z 








j 



A 

B 

C 

D 

E 




IT 


F 

G 

IT 


IT 

B 



F 

G 

L 

M 

N 

Y 

P 

H 

~l 

iri 

"o’ 


'Y 

~r" 

s 

T 

U 






V 

w 

X 

Y 

Z 












(13) The identifications given by these placements are inserted in tto text, and solution 
very rapidly completed. The final checkerboard and deciph^d text are given below. 


A 

B 

C 

D 

E 

s 

0 

c 

I 

E 

F 

G 

H 

I^ 

K 

T 

Y 

A 

B 

D 

L 

M 

N 

0 

P 

F 

G 

H 

K 

L 

Q 

R 

s 

T 

U 

M 

N 

P 

Q 

R 

V 

W 

X 

Y 

Z 

U 

V 

W 

X 

z' 

E 

X 

p 

U 

L 

A 

B 

C 

D 

E 




N 

T 

"f" 

nr 

IT 

rj 

K 

~b' 


D 

~F 

"g~ 

L 

M 

IT 

0 

nr 

IT 

K 

IT 


~R 

T 


s 

T 

nr 

T 

V 

w 

Y 

,-Z. 

V 

w 

IT 

Y 

z 


itoinni2M. 


A. H F C A P GOQIL BSPKM NDUKE OHQNF BORUN 

ONEHU NDRED FIRST FIELD ARTIL LERYF 

B. Q C L C H Q B Q B F H M A F X S I d K 0 Q t P M S X M C Y 

ROMPO SITIO NSINV 1C IN I 't Y 0 F B A R LOW 

C. XIFBE XAFDX LPMX H HR GKG QKQML FEQQI 

WILLB EINGE NERAL SUPPO RTSTO PDURI 

D. GOIHM UEORD CLTUF EQQCG QNHFX IFBEX 

NGATT ACKSP ECIAL ATTEN TIONW ILLBE 

E. FLBUQ FCHQO QMAFT XSYCB EPFNB SPKNU 

PAIDT OASSI STING ADVAN CEOFF IRSTB 

F. QITXE UQMLF EQQIG OIEUE HPIAN YTFLB 

RIGAD ESTOP DU R 1 N G A D V A N C E I T W I L L P f 

G. FEEPI DHPCG NQIHB FHMHF XCKUP DGQPN 

LACEC ONCEN TRATI ONSON WOODS NORTH 

H. CBCQL QPNFN PNITO RTENC CBCNT FHHAY 

ANDSO UTHOFTHAYE RFARM ANDHI LLSIX 

J. ZLQCI AAIQU CHTPC BIFGW KFCQS LQMCB 

ZEROE IGHTD ASHAA NDONW OODSE ASTAN 

K. OYCRQ QDPRX FNQML FIDGC CGIOG OIHHF 

DWEST THERE OFSTO PCOMM ENCIN GATON 

L. IRCGG GNDLN OZTFG EERRP IFHOT FHHAY 

ETENP MSMOK EWILL BEUSE DONHI LLSIX 

M. ZLQCI AAIQU CHTP 

ZEROE IGHTD ASHA 


d. (1) It b interesting to note how much simider the matter becomes when the positions 
of the plain-text and cipher-text sections are reversed, or, what amounts to the same thing, 
when in encipherment the plain-text pairs are sought in the sections containing the mixed alpha¬ 
bets, and their cipher equivalents are taken from the sections containing the normal alphabets. 
For example, referring to Fig. 23A, suppose that sections 3-4 be used as the source of the plain¬ 
text pairs, and sections 1-2 as the source of the cipher-text pairs. Then ONp=DG„ EI^=AU,, etc. 

(2) To solve a message enciphered in that manner, it is necessary merely to make a square 
in which all four sections are normal alphabets, and then perform two steps. First, the cipher text 
pairs are converted into their normal alphabet equivalents merely by “deciphering” the message 
with that square; the result of this operation yields two monoalidiabets, one composed Of the odd 
letters, the other of the even letters. The second step is to solve these two mono^alphabets. 

(3) Where the same mixed alphabet is inserted in sections 3 and 4, the problem is still 
easier, since the letters resulting from the conversion into normal-alphabet equivalents all belong 
to the same, single-mixed alphabet. 

45. Analysis of ciphers based upon other types of checkerboard designs.—^The sdution 
of cryptograms enciphered by other types of checkerboard designs is accomplished along lines 
very similar to those set forth in the foregoing example of the solution of a message prepared by 
means of a 4-square checkerboard design. There are, unfortunately, no means or tests which can 
be applied to determine in the early stages of the analysis exactly what type of design is involved 
in theArst case imder study. The author freely admits that the 8<dution outlined in subparagraph 
c is quite artificial in that nothing is demonstrated in step (7) that obviously leads to or warrants 
the assumption that a 4-Bquare checkerboard is involved. This point was passed over with the 
qmte bald statement that this was “the simplest thing to assume”—cmd thett the solution 
proceeds exactly as though this mere hypothesis has been definitely established.' For.e»iinple, the 
very first results obtained were based upon assuming that a certain 44etter repetition represented 
the word STOP and immediately inserting certain letters in appropriate cells in a ^-sgyaae tkecker- 
board. Several more assumptions were built on top Of that and very rapid strides w»e made. 
What if it had not been a 4-square checkerboard at all? What if it had bron a 2-8quare checker¬ 
board of the type shown in lig. 24? 


M 

A 

N 

u 

F 

0 

S 

Q 

L 

P 

C 

T 

R 

I 

G 

W 

Z 

Y 

V 

X 

B 

D 

E 

H 

K 

D 

K 

H 

B 

E 

L 

0 

l_P_ 

Q 

S 

A 

F 

U 

M 

N 

V 

JL 

X 

Y 

z 

T 

G 

I 

C 

R 


FlOXrBE2(. 

The only defense that can be made of what may seem to the student to be pmely arbitrary 
procedure based upon the author’s advance information or knowledge is the following: In the 
first place, in order to avoid making the explanation a too-long-drawn-out affair, it is necessary 
(and pedagogical experience warrants) that certain alternative hypotheses be passed over in 
silence. In the second place, it may now be added, after the principles and procedure have been 
elucidated (which at this stage is the primary object of this text) that if good results do not follow 
from a first hypothesis, the only thing the cryptanalyst can do is to reject that hypothesis, and 
formulate a second hypothesis. In actual practice he may have to reject a second, third, fourth, 
. . . nth hypothesis. In the end he may strike the right one—or he may not. There is no 
guaranty of success in the matter. In the third place, one of the objects of this text is to show 
how certain systems, if employed for military purposes, can readily be broken down. Assuming 







84 - 


that a checkerboard system is in use, and that daily changes in keywords are made, it is possible 
that the traffic of the first day might give considerable difficulty in solution, if the type of 
checkerboard were not known to the cryptanalyst. But the second or third day's traffic would 
be easy to solve, because by that time the cryptanalytic personnel would have analyzed the 
system and thus learned what type of checkerboard the enemy is using. 

46. Analysis of the Playfair cipher system.— a. An excellent example of a practical, partially 
digraphic system is the Playfair cipher.® It was used for a munber of years as a field cipher by 
the British Army, before and during the World War, and for a short time, also during that 
war, by certain units of the American Expeditionary Forces. 

h. Published solutions ’’ for this cipher are quite similar basically and vary only in minor 
details. The earliest, that by lieut. Mauborgne, used straightforward principles of frequency to 
establish the values of three or four of the most frequent digraphs. Then, on the assumption 
that in most cases m which a keyword appears on the first and second rows the last five letters 
of the normal alphabet, VWXYZ, wiU rarely be disturbed in sequence and will occupy the last row 
of the square, he “juggles” the letters given by the values tentatively established from frequency 
considerations, placing them in various positions iu the square, together with VWXYZ, to correspond 
to the plaintext cipher relationships tentatively established. A later solution by Lieut. Frank 
Moorman, as described in Hitt’s Manual, assumes that in a Playfair cipher prepared by means 
of a square in whidi the keyword occupies the first and second rows, if a digraphic frequency 
distribution is made, it wfil be foimd that the letters having the greatest combining power are 
very probably letters of the key. A still later solution, by Lieut. Commander Smith, is perhaps 
the iliiost lucid and systematized of the three. He sets forth in definite language certain con¬ 
siderations which the other two writers certainly entertained but failed to indicate. 

t. The following details have been summarized from Commander Smith’s solution: 

(1) The Playfair cipher may be recognized by virtue of the fact that it always contains an 
even number of letters, and that when divided into groups of two letters each, no group contains 
a repetition of the same letter, as NN or EE. Repetitions of digraphs, trigraphs, and polygraphs 
will be evident in fairly long messages. 

(2) Usiug the square ® shown in Fig. 25a, there are two general cases to be considered, as 
regards the results of encipherment: 


B 

A 

N 

K 

R 


E 

F 

G 

H 

I-J 

L 

M 

0 


u 




Y 

IJ 


W 

~Y 

~Z 


Vioim 2Sa. 


• This cipher was really invented by Sir Charles Wheatstone but receives its name from Lord Playfair, 
who apparently was its sponsor before the British Foreign Office. See Wemyss Reid, Memoirs of Lyon Playfair, 
London, 1899, A detailed description of this cipher will be found in Sec. VIII, Advanced Military Cryptograi^y. 

' Mauborgne, Lieut. J. 0., U. S. A. An advanced problem in cryptography and its solution, Leavenworth, 1914. 

Hitt, Captain Parker, U. S. A. Manual for the solution of military ciphers, Leavenworth, 1918. 

Smith, Lieut. Commander W. W., U. S. N. In Cryptography by Andrd Langie, translated by J. C. H. 
Macbeth, New York, 1922. 

’ The Playfair square accompanying Commander Smith’s solution is based upon the keyword BANKRUPTCY, 
“to be distributed between the first and fourth lines of the square.” This is a simple departure from the original 
Playfair scheme in which the letters of the keyword are written from left to right and in consecutive lines from 
the top downward. 


] 


Cabi!: 1. Letters at opposite comers of a rectangle. The following illustrative relationships 
are found: 

THp=YFe 

HTp=FY, 

YFp=TH, 

FYp=HTe 

Reciprocity is complete. 

Case 2. 'Two letters in the same line or column. The following illustrative relationships 
are found: 

ANpfNK, 

NA^KNo 

But NI^ does not=AN*, nor does KNp=NA,. 

Reciprocity is only partial. 

(3) The foregoing gives rise to the following: 

Rule I. (a) Regardless of the position of the letters in the square, if 
1.2=3.4, then 
2,1=4.3 

(6) If 1 and 2 form opposite comers of a rectangle, the following equations obtain: 


(4) A letter considered as occupying a position in a row can be combined with but four other 
letters in the same row; the same letter considered as occupying a position in a column can be 
combined with but four other letters in the same column. Thus, this letter can be combined with 
only 8 other letters all told, under Case 2, above. But the same letter considered as occupying 
a comer of a rectangle can be combined with 16 other letters, under Case 1, above. Commander 
Smith derives from these facts the conclusion that “it would appear that Case 1 is twice as prob¬ 
able as Case 2.” He continues thus (notation my own): 


‘Now in the square, note that: 



AN,fNK, 


ENifFA, 

GNp=FK, 


EIM,fFLp 

ONp==MK, 

also 

ETpsFP, 

CNp=TK, 


EWp=FV, 

XNp=WK, 


EF,fFGo 


“From this it is seen that of the 24 equations that can be formed when each letter of the 
square is employed either as the initial or final letter of the group, five will indicate a repetition of 
a corresponding letter of plain text. 

“Hence, Rule II. After it has been determined, in the equation 1.2=3.4, that, say, ENp=FA„ 
there is a probability of one m five that any other group beginning with F, mdicates EGp, and that 
any group ending in A, indicates 0Np. 


I 


.. 





86 


87 


“After such combinations as ERp, ORp, and ENp have been assumed or determined, the above 
rule may be of use in discovering additional digraphs and partial words.” • 

Rule III. In the equation 1.2=3.4, 1 and 3 can never be identical, nor can 2 and 4 ever be 
identical. Thus, ANp could not possibly be represented by AY,, nor could ERp be represented by KR*. 
This rule is useful in elimination of certain possibilities when a specific message is being studied. 

Rule IV. In the equation 1.2p=3.4c, if 2 and 3 are identical, the letters are all in the same 
row or column, and in the relative order 124. In the square showii, ANp=NKe and the absolute 
order is ANK. The relative order 124 includes five absolute orders which are cyclic permutations 
of one another. Thus: ANK.,, NK. .A, K. .AN, . .ANK, and .ANK.. 

Rule V. In the equation 1.2p=3.4c, if 1 and 4 are identical, the letters are all in the same 
row or column, and in the relative order 243. In the square shown, KNp=RKo and the absolute 
order is NKR. The relative order 243 includes five absolute orders which are cyclic permutations 
of one another. Thus NKR.., KR.. N, R.. NK, .. NKR, and . NKR.. 

Rule VI. “Analyze the message for group recurrences. Select the groups of greatest 
recurrence and assiune them to be high-frequency digraphs. Substitute the assumed digraphs 
throughout the message, testing the assumptions in their relation to other groups of the cipher. 
The reconstruction of the square proceeds simultaneously with the solution of the message and 
aids in hastening the translation of the cipher.” 

d. (1) When solutions for the Playfair cipher system were first developed, based upon the 
fact that the letters were inserted in the cells in keyword-mixed order, ciyptographers thought 
it desirable to place stumbling blocks in the path of such solution by departing from strict, 
keyword-mixed order. Playfair squares of the latter type are designed as “modified Playfair 
squares.” One of the simplest methods is illustrated in Fig. 26a, wherein it will be noted that 
the last five letters of the keyword proper are inserted in the fourth row of the sqmire instead 
of the second, where they would naturally fall. Another method is to insert the letters within 
the cells from left to right and top downward but use a sequence that is a keyword-mixed sequence 
developed by a columnar transposition based upon the keyword proper. Thus, using the key¬ 
word BANKRUPTCY: 

215479683 10 
BAN K R U P T C Y 
DEFGHILUOQ 
S V W X Z 

Sequence: AEVBDSCOKGXNFWPLRHZTMUIYQ 
* There is an error in this reasoning. Take, for example, the 24 equations having F as an initial letter: 


1. FB,=DNp 

Case 

2. FE=ED 

2. FT=NM 

1. 

FX=GW 

2. FD =EH 

1. FL=EII 

2. Fff=NT 

1. 

FR^HN 

1. FI =DM 

1. FP=ET 

1. FK=GN 

2. 

FH=EG 

1. FU =DT 

1. FV=EW 

2. FG=ra' 

1. 

FQ=HU 

1. FS =DW 

2. FN=NW 

1. F0=GM 

1. 

FY=HT 

1. FA =EN 

2. m=NF 

1. FG-GT 

1. 

FZ=HW 

Here, the initial letter F, represents the following initial letters of plain-text digraphs: 



The Playfair Square is as follows: 


A 

E 

V 

B 

D 

S 

C 

0 

K 

G 

X 

N 

F 

W 

P 

L 


IT 

~Z~ 

~T~ 

ITi 

IT 

~ 

~ 

T 


(2) In the foregoing square practically all indications that the square has been developed 
from a keyword have disappeared. The principal disadvantage of such an arrangement is that 
it requires more time to locate the letters desired, both in cryptographing and dec^rypt(^gaphii^, 
than it usually does when a semblance of normal alphabetic order is preserved in the square. 

(3) Note the following three squares: 



D E N G H 

It is seen that F, represents D„ Np, Gp, Hp 4 times each, and Ep, 8 times. Consequently, supposing that it has 
been determined that FA,=ENp, the probability that F, will represent Ep is not I in 6 but 8 in 24, or 1 in 3; but 
supposing that it has been determined that FWo=NTp, the probability that F, will represent Np is 4 in 24 or 1 in 6. 
The difference in these probabilities is occasioned by the fact that the first Instance, FA,=ENp corresponds to a 
Case 1 encipherment, the second instance, FW,=NTp, to a Case 2 encipherment. But there is no way of knowing 
initially, and without other data, whether one is dealing with a Case 1 or Case 2 encipherment. Only as an 
approximation, therefore, may one say that the probability of F, representing a given Op is 1 in 6. 







88 

At first glance they all appear to be different, but closer examination shows them to be eydic 
permutations of one another and of the square in Fig. 266. They yield identical equivalents in 
all cases. However, if an attempt be made to reconstruct the original keyword, it would be 
much easier to do so from Fig. 256 than from any of the others, because in Fig. 256 the keyword- 
mixed sequence has not been disturbed as much as in Figs. 26c, d, «. In working with Playfair 
ciphers, the student should be on the lookout for such instances of cyclic permutation of the 
original Playfair square, for during the course of solution he will not know whether he is building 
up the original or an equivalent cyclic permutation of the original square; only after he has 
completely reconstructed the square will he be able to determine this point. 

(4) It can readily be shown that the colunms of a Playfair square may be cyclically permuted 
(see subpar. d) to produce a first set of 25 squares all of which, though at first glance apparently 
different, will yield identical equivalents; likewise, the rows of such a square may be cyclically 
permuted to produce a second set of 25 squares all of which will also yield identical equivalents. 
Thus there may be a total of 50 cyclic permutations composed of two seta of 25 each. The 
cipher equivalents yielded by Case 2 encipherments (letters in the same row or in the same 
colqnm) will be identical for any two of these 50 different Playfair squares; but the cipher equiv¬ 
alents yielded by Case 1 encipherments (letters at diagonally opposite corners of a rectangle) 
will be identical only for two squares belonging to the same set of 25 cyclic permutations. 

«. ^1) The eteps in the solution of a typical example of this cipher may be useful. Let 
the miss^e be follows: 



1 


t 

4 ( 

8 

1 

8 

« 

10 

11 

u 

« 

14 

18 

U 17 

u 

10 


n 

s 

a 

a 

a 

a 37 a a w 

A. 

V ,T Q E U 

H 

I 

0 

F 

T 

C 

H X 

X 


A K 

T V T 

R A 

Z E V 

T A G A E 

B. 

0 

XT 

Y H 

H 

C R 

L Z 

Z 

T Q T 

D 

U If 

C 

Y 

C 

X 

C 

T 

G M 

T Y C Z U 

C. 

S 

N 

0 

P D 

G X V 

X 

S 

_C. 

A K 

T V 

JL P 

K 

P 

U 

T 

Z 

P 

T 

W 

Z F N B G 

D. 

P 

T R K X 

I 

X 

B 

P R 

z 

0 

E 

P 

U 

T 0 

L 

Z 

E 

K T 

T 

C 

S 

N H C Q M 

1 E. V 

T R K M 

W 

c 

F 

Z 

U 

B 

H 

T 

V 

Y 

A B 

G 

I 

P 

R 

z 

K 

P 

C 

Q F N L V 

F. 

0 

X 

0 

T U 

z 

L 

A 

A 

JL 

JL 

_C. 

_P_ 

X 

X 

-H C 

Y 

N 

0 

T 

Y 

0 

L 

G 

X X I I H 

G. 

T 

M 

s 

M X_ 

_c_ 

jp. 

X 

X 

X. 

_c_ 

X 

J. 

JL 

T 

C Y 

A 

T 

E 

X 

H 

L 

X 


X X C P Z, 

H. 

,X H 

Y 

C T 

X 

w 

L 

Z 

T 

s 

G 

P 

z 

T 

V Y 

W 

C 

E 

T 

W 

G 

c 

C 

M B H M Q 

J. 

Y 

X 

Z 

P W 

G 

R 

T 

I 

V 

u 

X 

P 

U H 

Q R K 

M 

W 

C 

X 

T M R 

S W G H B 

K. 

X 

_c. 

X. 

T 0 

JL 

_C. 

X 

A 

Jl 

H 

I 

P 

Y 

D 

N F 

G 

K 

I 

T 

c 

0 

L 

X 

U E T P X 

L. 

X 

F 

S 

R S 

u z 

T 

D 

B 

H 

0 

Z 

I 

G 

X R 

K 

I 

X 

Z 

p 

P 

V Z 

I D U H Q 

M. 

0 

T 

K 

T K 

c 

C H X X 

















89 

(2) Without going through the preliminaiy tests in detful, with which it will be asisumed 
that the student is now famihar,**’ the conclusion is reached that the cryptogram is digraphic in 
nature, and a digraphic frequency distribution is made (Fig. 26). 


ABCDEFGHIKLMNOP QRSTUVWXYZ 



» See Par. 44c. 










(7) It is perhaps high time that the whole list of tentative equivalent values be studied in 
relation to their consistency with the positions of letters in the Playfair square; moreover, by so 
doing, additional values may be obtained in the process. The complete list of values is as follows: 


Atsumed values 
AT^CX, 
LI^PZ, 
ON^XH. 
THp=OT, 
IRtf=UZ. 
DBp=FA, 
ECp=TE, 

TEjPPT, 

EIjpTC. 

RS^YA, 

-S^M, 


Derived by Rule I 

TA^XC. 

ILp=ZP, 

NO^HX. 

HTp=T0. 

RI,pZU, 

BDp=AF, 

CE„=ET, 

ETpFTP, 

IEp=CT. 

SR^AY. 

S-^MS, 


(8) By Rule V, the equation THp=0T, means that H, T, and 0 are all in the same row or col¬ 
umn and in the relative order 2-4-3; similarly, C, E, and T are in the same row or column and in the 
relative order 243. Fxirther E, P, and T are in the same row and colmnn, and their relative 
order is also 243. That is, these sequences must occur in the square: 


( 1 ) 

H T 0 . . , or 
TO. . H , or 
0 . . H T , or 
. . H T 0 , or 
. H T 0 . 


( 2 ) 

GET. . , or 

E T . . C , or 

T . . C E , or 

. . C E T , or 

.GET. 


(3) 

E T P . . , or 
TP. . E , or 
P . . E T , or 
. . E T P . or 
. E T P . 


(9) Noting the common letters E and T in the second and third sets of relative orders, these 
may be combined into one sequence of four letters. Only one position remains to be filled and 
noting, in the list of equivalents that EIp=TGc, it is obvious that the letter I belongs to the GET 
sequence. The complete sequence is therefore as follows: 


G E T P I . or 
E T P I G , or 
T P I G E , or 
P I G E T , or 
I G E T P 


(10) Taking up the HTO sequence, it is noted, in the list of equivalents that 0Np=XHe, an 
equation containing two of the three letters of the HTO sequence. From this it follows that 
N and X must belong to the same row or colunm as HTO. The arrangement must be one of the 
following: 

H T 0 X N 

T 0 X N H 

0 X N H T 

X N H T 0 

N H T 0 X 

(11) Since the sequence containing HTOXN has a common letter (T) with the sequence 
GETPI, it follows that if the HTOXN sequence occupies a row, then the GETPI sequence must 
occupy a colunm; or, if the HTO sequence occupies a colunm, then the GETPI sequence must 


occupy a row; and they may be combined by means of their common letter, T. According to 
subpar. d (4), the two sequences may be inserted within a Playfair square in 25 different ways 
by cyclically permuting and shifting the letters of one of these two sequences; and the same 
two sequences may be again inserted in another set of 25 ways by cyclically permuting and 
shifting the letters of the other of these two sequences. In Fig. 27 the diagrams labeled (1) 
to (10), inclusive, show 10 of the possible 25 obtainable by making the HTOXN sequence one 
of the rows of the square; diagrams (11) and (12) show 2 of the possible 25 obtainable by making 
the HTOXN sequence one of the coliunns of the square. The entire complement of 25 arrange¬ 
ments for each set may easily be drawn up by the student; space forbids their being completely 
set forth and it is really unnecessary to do so. 


(1) (2) (3) (4) 











94 


i 

I 


(12) Before trying to discover means whereby the actual or absolute arrangement may 
be detected from among the full set of 50 possible arrangements, the question may be raised: is 
it necessary? So far as concerns Case 2 encipherments, since any one of the 50 arrangements 
wiU yield the same equivalents as any of the remaining 49, perhaps a relative arrangement 
will do. 

(13) Let arrangement 8 be arbitrarily selected for trial. 



(14) What additional letters can be inserted, using as a guide the hst of equivalents in sub- 
paragraph (7)? There is ATp=CXo, for example. It contains only one letter. A, not in the 
arrangement selected for trial, and this letter may immediately be placed, as shown:’® 



FiOVBI 28A. 


Scanning the list for additional cases of this type, none are found. But seeing that several high- 
frequency letters have already been inserted in the square, perhaps reference to the cryptograhi 
itself in connection with values derived from these inserted letters may yield further clues. For 
example, the vowels A, E, I, and 0 are all in position, as are the very frequent consonants N and T. 
The following combinations may be studied: 


ANp=eXc 

ATp=CXe 

NA^Xe, ■ 

TAp=XC. 

ENp=eTo 

ETp=TPo 

NEp=Tee 

TEp=PT, 

iNp=eTo 

ITp=CPo 

NI„=Te„ 

TIp=PC. 

o 

1 

0Tp=X0„ 

N0p=HXe 

o 

II 


ATp(=CXe), TAp(=XC.), 0Np(=XH„), TEp(=PTc) and ETp(=TPe) have already been inserted in the 
text. Of the others, only 0Xc(=T0p) occurs two times, and this value can be at once inserted in 
the text. But can the equivalents of AN, EN, or IN be found from frequency considerations? 

The fact that the placement of A yields ATp = CX„ means that the outline selected for experiment really 
belongs to the correct set of 25 possible cyclic permutations, and that the letters of the NHTOX sequence belong 
in a row, the letters of the PICET sequence belong in a column of the original Playfair square. If the reverse 
were the case, one could not obtain AT„ = CXe but would obtain ATp=XCo. 



95 


Take ENp, for example; it is represented by OTp. What combination of 6T is most likely to repre¬ 
sent ENp among the following candidates: 

KTc (4 times); by Rule I, NEp would=TKo (no occurrences) 

VTo (5 times); by Rule I, NEp would=TVc (2 times) 

ZTc (3 times); by Rule I, NEp would=TZe (1 time) 

VTo certainly looks good: it begins the message, suggesting the word ENEMY; in line H, in the 
sequence PZTV would become LINE. Let this be assumed to be correct, and let the word ENEMY 
also be assumed to be correct. Then EMp=QEo and the square then becomes as shown herewith: 



(15) In line E is seen the following sequence: 

Line E:.VT RK MW CF ZU BH TV YA BG IP RZ KP CQ FN LV 

EN RI NE RS PT E 

The sequence . . .RI. .NERS. .PT. . . suggests PRISONERS CAPTURED, as follows: 

MW CF ZU BH TV YA BG IP RZ KP 
P RI SO NE RS CA PT UR ED 

This gives the following new values: 0Pp=CFo; SOp=BHo; CAp=BGo; URp=RZc; EDp=KPo. 

The letters B and G can be placed in position at once, since the positions of C and A are already 
known. The insertion of the letter B immediately permits the placement of the letter S, from the 
equation S0p=BHc. Of the remaining equations only EDp=KPo can be used. Since E and P are 
fixed and are in the same column, D and K must be in the same column, and moreover the K must 
be in the same row as E. There is only one possible position for K, viz, immediately after Q. This 
automatically fixes the position of D. The square is now as shown herewith: 



FIOUEK 28<i. 















96 


(16) A review of all equations, including the very first ones established, gives the following 
which may now be used: DBp=FAe; RSp=YAa. The first permits the immediate placement of F; 
the second, by elimination of possible positions, permits the placement of both R and Y. The 
square is now as shown herewith: 



FioOBI 2Se. 

Once more a review is made of all remaining thus far unused equations, LIp=PZe now permits 
the placement of L and Z. IRp=UZc now permits the placement of U, which is confirmed by the 
equation URp==RZ, from the word CAPTURED. 


L 


P 

F 

D 

Z 

Y 

I 

U 

R 

G 

S 

C 

B 

A 

V 

M 

E 

Q 

K 

N 

H 

T 

0 

X 


Hqubi 2tf. 


There is then only one cell vacant, and it must be occupied by the only letter left unplaced, 
viz; W. Thus the whole square has been reconstructed, and the message can now be decrypto- 
graphed. 

(17) Is the square just reconstructed identical with the original, or is it a cyclic permuta¬ 
tion of a keyword-mixed Playfair square of the type illustrated in Fig. 256? Even though the 
message can be read with ease, this point is still of interest. Let the sequence be written in five 
ways, each composed of five partial sequences made by cyclicly permuting each of the horizontal 
rows of the reconstructed square. Thus: 

Kow 1 Row 2 Row 3 Row 4 Row 5 

(a) LWPFD ZYIUR GSCBA VMEQK NHTOX 

(b) WPFDL YIURZ SCBAG MEQKV HTOXN 

(c) PFDLW lURZY CBAGS EQKVM TOXNH 

(d) FDLWP URZYI BAGSC QKVME OXNHT 

(e) DLWPF RZYIU AGSCB KVMEQ XNHTO 


§7 


By experimenting with these five sequences, in an endeavor to reconstruct a transpoation 
rectangle conformable to a keyword sequence, the last sequence yields the following: 

P Y A C M N 
D F I G B E H 

L R U S K Q T 

W Z VXD 

By shifting the 0 from the last position to the first, and rearranging the columns, the following 
is obtained: 

2 5 3 6 1 4 7 
COMPANY 
B D E F G H I 

K L Q R S T U 

V W X Z 


The original square must have been this; 



navKt Vt 


j. Continued practice in the solution of Playfair ciphers will make the student quite expert 
in the matter and will enable him to solve shorter and shorter messages." Also, with practice 
it will become a matter of indifference to him as to whether the letters are inserted in the square 
witii any sort of regularity, such as simple keyword-mixed order, columnar transposed keyword- 
mixed order, or in a purely random order. , 

g. It may perhaps seem to the student that the foregoing steps are soniewhat too artificial, 
a bit too “cut and dried” in their accuracy to portray the process of analysis, as it is applied in 
practice. For example, the critical student may well object to some of the assumptions and the 
reasoning in step (5) above, in which the words THREE and ONE (1st hypothesis) were rejected 
in favor of the words THIRD and SECOND (2nd hypothesis). This rested largely upon the 
rejection of REp and ERp as the equivalents of UZo and ZUc, and the adoption of IRp and Rip as 
their equivalents. Indeed, if the student wiU examine the final message with a critical eye he 
will find that whUe the bit of reasoning in step (6) is perfectly logical, the assumption upon which 
it is based is in fact wrong, for it happens that in this case ERp occurs only once and REp does not 
occur at all. Consequently, although most of the reasoning which led to the rejection of the 1st 
hypothesis and the adoption of'the 2nd was logical, it was in fact based upon erroneous assump- 

11 The author once had a student who "specialised” In Playfair ciphers and became so adept that he could 
solve messages containing as few as 60-60 letters within 30 minutes. 











98 


tion. In other words, despite the fact that the assumption was incorrect, a correct deduction 
was made. The studerd shovld take note that in cryptanalysis situations oj this sort are not at all un¬ 
usual. Indeed they are to be expected and a few words of explanation at this point may be useful. 

h. Cryptanalysis is a science in which deduction, based upon observational data, plays a 
very large role. But it is also true that in this science most of the deductions usuaDy rest upon 
assumptions. It is most often the case that the cryptanalyst is forced to make his assumptions 
upon a quite hmited amount of text. It cannot be expected that assumptions based upon 
statistical generalizations will always hold true when applied to data comparatively very much 
smaller in quantity than the total data used to derive the generalized rules. Consequently, as 
regards assumptions made in specific messages, most oJ the time they will be correct, but occa¬ 
sionally they will be incorrect. In cryptanalysis it is often found that among the correct deduc¬ 
tions there will be cases in which subsequently discovered facta do not bear out the assumptions 
on which the deduction was based. Indeed, it is sometimes true that if the/ads had beenknown 
hejore the deduction was made, this knowledge would have prevented making the correct deduc¬ 
tion. For example, suppose the cryptanalyst had somehow or other divined that the message 
under consideration contained no RE, only one ER, one IR, and two RI’s (as is actually the case). 

He would certainly not have been able to choose between the words THREE and ONE (1st hypo¬ 
thesis) as against THIRD and SECOND (2d hypothesis). But because he assumes that there 
should be more ERp’s and REp’s than IR’s and RI’s in the message, he deduces that UZ, cannot 
be REp, rejects the 1st hypothesis and takes the 2d. It later turns out, after the problem has been 
solved, that the deduction was correct, although the assumption on which it was based (expectation 
of more frequent appearance of REp and ERp) was, in fact, not true in this particular case. The 
cryptanalyst can only hope that the number of times when his deductions are correct, even though 
based upon assumptions which later turn out to bo ei^neous, will abundantly exceed the num¬ 
ber of times when his deductions are wrong, even though based upon assumptions which later 
prove to be correct. If he is lucky, the making of an assumption which is really not true will 
make no difference in the end and will not delay solution; but if he is specially favored with 
luck, it may actually help him solve the message—as was the case in this particular example. 

i. Another comment of a general nature may be made in connection with this specific 
example. The student may ask what would have been the procedure in this case if the message 
had not contained such a teU-taJe repetition as the word BATTALION, which formed the point 
of departure for the solution, or, as it is often said, permitted an "entering wedge" to be driven 
into the message. The answer to his query is that if the word BATTALION had not been repeated, 
there would probably have been some other repetition which would have permitted the same 
sort of attack. If the student is looking for cut and dried, straight-forward, unvarying method 
of attack, he should remember that cryptanalysis, while it may he considered a branch of mathe¬ 
matics, is not a science which has many "general solutions” such as are found and expected in / 
mathematics proper. It is inherent in the very nature of cryptanalytics that, as a rule, only 
general principles can be established; their practical application must take advantage of peculi¬ 
arities and particular situations which are noted in specific messages. This is especially true in 

a text on the subject. The illustration of a general principle requires a specific example, and the 
latter must of necessity manifest characteristics which make it different from any other example. 

The word BATTALION was not purposely repeated in this example in order to make the demon¬ 
stration of solution easy; “it just happened that way." In another example, some other entering 
wedge would have been found. The student can be expected to learn only the general principles 
which will enable him to take advantage of the specific characteristics manifested in specific cases. 

Here it is desired to illustrate the general principles of solving Playfair ciphers and to point out 
the fact that entering wedges must and can be foimd. The specific nature of the entering wedge 
varies with specific examples. 


Section X 

CONCLUDING REMARKS 

Paragraidi 


Special remarks concerning the initial classification of cryptograms..-. 

Ciphers employing characters other than letters or figures—.—. ... "49 

Concluding remarks concerning monoalphabetic substitution..—... 

Analytical key for cryptanalysis........- . 


47. Special remarks concerning the initial classification of cryptograms.—a. The student 
should by this time have a good conception of the basic nature of monoalphabetic substitution ^d 
of the many "changes” which may be rung upon this simple tune. The first step of all, naturally, 
b to be able to classify a cryptogram properly and place it in either the transposition or the 
substitution class. The tests for this classification have been given and as a rule the student 
will encounter no difficulty in this respect. , , . • j 

b There are, however, certain kinds of cryptograms whose class cannot be determined m the 
usual manner, as outlined in Par. 13 of this text. First of all there is the type of code iness^e 
which employs bona-fide dictionary words as code groups.* Naturally, a frequency distnbution 
of such a message will approximate that for normal plain text. The appearance of the message, 
however, gives clear mdications of what is involved; The study of such cases wiU be taken up in 
its proper place. At the moment it is only necessary to pomt out that these are code messages and 
not cipAer; and it is for this reason that in Pars. 12 and 13 the words "cipher" and cipher mes¬ 
sages” are used, the word "cryptogram” being used only v^re.tehhnically correct, 

c Secondly, there come the unusual and borderline cases, including c^tqgrams whose 
nature and type can not be ascertained from fr^uency distributions. Here, the cr^tograms Me 
technicaUy not ciphers but special forms of disguised secret writings which are rarely susceptible 
of being classed as transposition or substitution. These include a large share of the cases wherein 
the cryptographic messages are disguised and carried under an external, innocuous text wffich is 
innocent and seemingly without cryptographic content—for instance, m 
specific letters are indicated in a way not open to suspicion under censorship, these lettere bemg 
intended to constitute the letters of the cryptographic message and the other letters constitutmg 
“dummies." Obviously, no amount of frequency tabulations will av^ a competent, expert 
cryptanalyst in demonstrating or disclosing the presence of a cryptograpffic m^age, wntt® and 
secreted within the "open" message, which serves but as an envdop and disgmse for ite authentic 
or real import. Certainly, such frequency tabulations can disclose the existence vsdher of sub¬ 
stitution nor transposition in these cases, since both forms are absent. Another ve^popular 
method that resembles the method mentioned above has for its basis a simple gnUe The whole 
words forming the secret text are inserted within perforations cut m the paper and the remainmg 
space filled carefully, using "nulls” and “dummies”, making a see^gly innocuous, or<J“ary 
in^essage. There are other methods of this general type which can obviously neither be detected 
nor cryptanalyzed, using the principles of frequency of recurrences and repetition These can 
not be further discussed herein, but at a subsequent date a special text may be written for their 
handling.* 

t See Sec. XV, Elementary MilUary Cryptography. „„„„„„ With 

» The subparagraph which the student has just read {47c) contains a hidden cryptographic message. With 
the hints given in Par. 35e let the student see if he can find it. 

(99) 









48. Ciphers employing characters other than letters or figures.— a. In view of the fore¬ 
going remarks, when so-called symbol ciphers, that is, ciphers employing peculiar symbols, 
signs of punctuation, diacritical marks, figures of “dancing men”, and so on are encoimtered 
in practical work nowadays, they are almost fiferlain to be simple, monoalphabetic ciphers. 
They are adequately described in romantic tales,® in popular books on cryptography, and in 
tiie more common types of magazine articles. No further space need be given ciphers of this 
iype in this text, not only because of their simplicity but also because they are encountered 
in military cryptography only in sporadic instances, principally in censorship activities. Evmi 
in the latter cases, it is usually found that such ciphers are employed in “intimate” correspondence 
for the exchange of sentiments that appear less decorous when set forth in plain language. They 
are very seldom uSed by authentic enemy agents. When such a cipher is encountered nowadays 
it may practically always be r^arded as the work of the veriest tyro, when it is not that of a 
"crank” or a mentally-deranged person. 

h. The usual preliminary procedure in handling such cases, where the symbols may be some¬ 
what confusing to the mind because of their unfamiliar appearance to the eye, is to substitute 
letters for them consistently throughout the message and then treat the resulting text as an ordi- 
h^ ciypfogram coihi)osed of letters is treated. This procedure also facilitates the construction 
of tihie necessary frequency distributiOM, which would be tedious to construct by using symbols, 

c. A fmal word iriuSt be said on the subject of symbol ciphers by way of caution. When 
Symbols are iiSed to replace letters, syllables, and entire words, then the systems approach code 
methocis in {Principle, and can beccnie difi&ciilt of solution.® The logical extension of the use of 
symbols in siich a fdrm of writing is the employment of arbitrary characters for a 8l>eeially 
developed “shorthahd” system bearing Kttle or no resemblance to well-known, and therefore 
nonsecret, systems of shorthand,' stmli' is Gregg, Pitman, etc. Unless a considerable amotint 
of text is available for analysis, a pritately-devised shorthand may be very difficult to solve. 
Fortunately, such systems are rarely encountered in military cryptography. They fall imder the 
heading of cryptographic curiosities, of interest to the cryptanalyst in his leisure moments.* 

d. In practical crypto^aphy today, as has been stated above, the use of characters other 
than the 26 letters of the English alphabet is comparatively rare. It is true that there are a 
few governments which still adhere to systems yielding cryptograms in groups of figures. These 
are almost in every case code systems and will be treated in their proper place. In some caseO 
cipher systems, or systems of enciphering code are used which are basically mathematical in 
character and operation, and therefore use numbers instead of letters. Some persons are 
inclined toward the use of numbers rather than letters because numbers lend themselves much 
more readily to certain arithmetical operations such as addition, subtraction, and so on, than 
do letters.* But there is usually added some final process whereby the figure groups are con¬ 
verted into letter groups, for the sake of economy in transmission. 

* The moet famoufl: Poe’s The Gold Bug; Arthur Conan Doyle’s The Sign of Four. 

* The use of symbols for abbreviation and speed in writing goes back to the days of antiquity. Cicero is 
reported to have drawn up “a book like a dictionary, in which he placed before each word the notation (symbol) 
which should represent it, and so great was the number of notations and words that whatever could be written in 
Latin could be expressed in his notations.” 

* Am example is found in the famous Pepys Diary, which was written in shorthand, purely for his own eyes 
by Samuel Pepys (1633-1703). “He wrote it in Shelton’s system of taehygraphy (1641), which he complicated 
by using foreign languages or by varieties of his own invention whenever he had to record passages least fit to be 
seen by his servants, or by ‘all the world.’ ” 

* But, this of course, is because we are taught arithmetic by using numbers, based upon the decimal system 
as a rule. By special training one could learn to perform the usual "aiithmetical” operations using letters. 
For example, using our English alphabet of 26 letters, where A=l, B=2, 0=3, etc., it is obvious that A+B=C, 
just as 1+2=3; (A+B)*=I, etc. This sort of cryptographic arithmetic could be learned by rote, just as 
multiplication tables are learned- 


e. The only notable exceptions to the statement contained in the first sentence of tte pre¬ 
ceding subparagraph are those of Eussian messages transmitted in the Kussian Morse alphabet 
and Japanese messages transmitted in the Kata Kana Morse alphabet. As regards Chihese, 
which is not an alphabetical language and comprises some 40,000 ideographs, since the Morse 
telegraph code comprises only some 40 combinations, telegrams in Chinese are usually prepArfed 
by means of codes which permit of substituting arbitrarily-assigned code groups for the char¬ 
acters. Usually the code groups consist of figures. One such code known as the Official Chinese 
Telegraph Code, has about 10,000 4-figure groups, beginning with 0001, and these are arranged 
so that there are 100 characters on each page. Sometimes, for purposes of secrecy or economy, 
these figure groups are enciphered and converted in letter groups. 

49 . Concluding remarks concerning monoalphabetic substitution.— a. The alert student will 
have by this time gathered that the solution of'monoalphabetic substitution ciphers of the simple 
or fixed type are particularly easy to solve, once the imderlying principles are thoroughly under¬ 
stood. As in other arts, continued practice with examples leads to facility and skill in solution, 
especially where the student concentrates his attention upon traffic all of the same general natui’e, 
so that the type of text which he is continually encountering becomes familiar to him and its 
peculiarities or characteristics of construction give clues for short cuts to solution. It is true 
that a knowledge of the general phraseology of messages, the kind of words used, their sequences, 
and so on, is of very great assistance in practical work in all fields of cryptanalysis. The student 
is urged to note particularly these finer details in the course of his study. 

6. Another thing which the student should be on the lookout for in simple monoalphabetic 
substitution is the consecutive use of several different mixed cipher alphabets in a single long 
message. Obviously, a single, composite frequency distribution for the whole message will not 
show the characteristic crest and trough appearance of a simple monoalphabetic cipher, since a 
given cipher letter will represent different plain-text letters in different parts of the message. 
But if the cryptanalyst will carefully observe the distribution as it is being compiled, he will 
note that at first it presents the characteristic crest and trough appearance of monoalphabeticity, 
and that after a time it begins to lose this appearance. If possible he should be on the lookout 
for some peculiarity of grouping of letters which serves as an indicator for the shift from one 
cipher alphabet to the next. If he finds such an indicator he should begin a second distribution 
from that point on, and proceed until another shift or indicator is encountered. By thus isolating 
the different portions of the text, and restricting the frequency distributions to the separate 
monoalphabets, the problem may be treated then as an ordinary simple monoalphabetic sub¬ 
stitution. Consideration of these remarks in connection with instances of this kind leads to the 
comment that it is often more advisable for the cryptanalyst to compile his own data, than to 
have the latter prepared by clerks, especially when studying a system de novo. For observations 
which will certainly escape an untrained clerk can be most useful and may indeed facilitate 
solution. For example, in the case under consideration, if a clerk should merely hand the tmi- 
literal distribution to the cryptanalyst, the latter might be led astray; the appearance of the 
composite distribution might convince him that the cryptogram is a good deal more complicated 
than it reaUy is. 

e. Monoalphabetic substitution with variants represents an extension of the basic principle, 
with the intention of masking the characteristic frequencies resulting from a strict monoalpha¬ 
beticity, by means of which solutions are rather readily obtained. Some of the subtferfuges 
applied on the establishment of variant or multiple values are simple and more or less fail to 
serve the purpose for which they are intended; others, on the contrary, may interpose serious 
difficulties to a straightforward solution. But in no case may the problem be considered of more 
than ordinary difficulty. Furthermore, it should be recognized that where these subterfuges 




102 

are really adequate to the purpose, the complications introduced are such that the practical 
manipulation of the system becomes as difficult for the cryptographer as for the cryptanalyst. 

d. As already mentioned in monoalphabetic substitution with variants it is most common 
to employ figures or groups of figures. The reason for this is that the use of numerical groups 
seems more natural or easier to the iminitiated than does the use of varying combinations of 
letters. Moreover, it is easy to draw up cipher alphabets in which some of the letters are 
represented by single digits, others by pairs of digits. Thus, the decomposition of the cipher 
text which is an irregular intermixture of imiliteral and multiliteral equivalents, is made more 
complicated and correspondingly difficult for the cryptanalyst, who does not known which 
digits are to be used separately, which in pairs. 

e. A few words may be added here in regard to a method which often suggests itself to lay¬ 
men. This consists in using a book possessed by all the correspondents and indicating the letters 
of the message by means of numbers referring to specific letters in the book. One way consists 
in selecting a certain page and then giving the line number and position of the letter in the line, 
the page number being shown by a single initial indicator. Another way is to use the entire 
book, giving the cipher equivalents in groups of three numbers representing page, line, and 
number of letter. (Ex.: 75-8-10 means page 76,8th line, 10th letter in the line.) Such systems 
are, however, extremely cumbersome to use and, when the cryptographing is done carelessly, 
can be solved. The basis for solution in such cases rests upon the use of adjacent letters on the 
same line, the accidental repetitions of certain letters, and the occurrence of imenciphered words 
in the messages, when laziness or fatigue intervenes in the cryptographing.' 

y. It may also be indicated that human nature and the fallibility of cipher clerks is such 
that it is rather rare for an encipherer to make full use of the complement of variants placed 
at his disposal. The result is that in most cases certain of the equivalents will be used so iquch 
more often than others that diversities in frequencies will soon manifest themselves, affording 
important data for attack by the cryptanalyst. 

g. In the World War the cases where monoalphabetic substitution ciphers were employed 
in actual operations on the Western Front were exceedingly rare because the majority of the 
belligerents had a fair, knowledge of cryptography. On the Eastern Front, however, the exten¬ 
sive use, by the poorly prepared Kussian Army, of monoalphabetic ciphers in the fall of 1914 
was an important, if not the most important, factor in the success of the German operations 
during the Battle of Tannenberg.® It seems that a somewhat more secmre cipher system was 
authorized, but proved too difficult for the untrained Kussian cryptographic and radio personnel. 
Consequently, recourse was had to simple substitution ciphers, somewhat interspersed with 
plain text, and sometimes to messages completely in plain language. The damage which this 
faulty use of cryptography did to the Russian Army and thus to the Allied cause is incalculabl 

h. Many of the messages found by censors in letters sent by mail during the World War 
were cases of monoalphabetic substitution, disguised in various ways. 

’ In 1916 the German Government conepired with a group of Hindu revolutionaries to stir up a rebellion in 
India, the purpose being to cause the withdrawal of British troops from the Western Front. Hindu conspirators 
in the United States were given money to purchase arms and ammunition and to transport them to India. For 
communication with their superiors in Berlin the conspirators used, among others, the system described in this 
paragraph. A 7-page typewritten letter, built up from page, line, and letter-number references to a book known 
only to the communicants, was intercepted by the British and turned over to the United States Government 
for use in connection with the prosecution of the Hindus for violating our neutrality. The author solved this 
message without the book in question, by taking full advantage of the clues referred to. 

• Gyld6n, Yves. Chifferbydernas Insataer I Vdrldskriget Till Lands, Stockholm, 1931. A translation under 
the title The Contribution of the Cryptographic Bureaus in the World War, appeared in the Signal Corps Bulletin 
in seven successive installments, from November-December 1933 to November-December 1934, inclusive. 

Nikolaieflf, A. M. Secrei, Causes of German success on the Eastern Front. Coast Artillery Journal, September- 
October, 1935. 


103 

60. Analytical key for cryptanalysis. — a. It may be of assistance to indicate, by means of an 
outline, the relationships existing among the various cryptographic systems thus far considered. 
This graphic outline will be augmented from time to time as the different cipher systems are 
examined, and will constitute what has already been alluded to in Par. &d and there termed an 
analytical key for cryptanalysis.* Fundamentally its nature is that of a schematic classification 
of the different systems examined. The analytical key forms an insert at the end of the book. 

b. Note, in the analytical key, the rather clear-cut, dichotomous method of treatment; that 
is, classification by subdivision into pairs. For example, in the very first step there are only 
two alternatives: the cryptogram is either (1) cipher, or (2) code. If it is cipher, it is either 
(1) substitution, (2) transposition. If it is a substitution cipher, it is eithw (1) monographic, 
or (2) polygraphic—and so on. If the student will study the analytical key attentively, it will 
assist him in fixing in mind the manner in which the various systems covered thus far are related 
to one another, and this wiU be of benefit in clearing away some of the mental fog or haziness 
from which he is at first apt to suffer. 

c. The numbers in parentheses refer to specific paragraphs in this text, so that the student 
may readily turn to the text for detailed information or for purposes of refreshing his memory 
as to procedure. 

d. In addition to these reference numbers there have been affixed to the successive steps 
in the dichotomy, numbers that mark the “routes” on the cryptanalytic map (the analytical 
key) which the student cryptanalyst should follow if he wishes to facilitate his travels along the 
rather complicated and difficult road to success in cryptanalysis, in somewhat the same way in 
which an intelligent motorist follows the routes indicated on a geographical map if he wishes to 
facilitate his travels along unfamiliar roads. The analogy is only partially valid, however. 
The motorist usually knows in advance the distant point which he desires to reach and he pro¬ 
ceeds thereto by the best and shortest route, which he finds by observing the route indications 
on a map and following the route markers on the road. Occasionally he encoimters a detour 
but these are unexpected difficulties as a rule. Least of all does he anticipate any necessity for 
journeys down what may soon turn out to be blind alleys and “dead-end” streets, forcing him 
to double back on his way. Now the cryptanalyst also has a distant goal in mind—the solution 
of the cryptogram at hand—^but he does not know at the outset of his journey the exact spot 
where it is located on the cryptanalytic map. The map contains many routes and he proceeds 

• This analytical key is quite analogous to the analytical keys usually found in the handbooks biologists 
commonly employ in the classification and identification of living organisms. In fact, there are several points 
of resemblance between, for example, that branch of biology called taxonomic botany and cryptanalysis. In 
the former the first steps in the classificatory process are based upon observation of externally quite marked 
differences; as the process continues, the observational details become finer and finer, involving more and more 
diflBculties as the work progresses. Towards the end of the work the botanical taxonomist may have to dissect 
the specimen and study internal characteristics. The whole process is largely a matter of painstaking, accurate 
observation of data and drawing proper conclusions therefrom. Except for the fact that the botanical taxonomist 
depends almost entirely upon ocular observation of characteristics while the cryptanalyst in addition to observa¬ 
tion must use some statistics, the steps taken by the former are quite similar to those taken by the latter. It is 
only at the very end of the work that a significant dissimilarity between the two sciences arises. If the botanist 
makes a mistake in observation or deduction, he merely fails to identify the specimen correctly; he has an 
"answer”—but the answer is wrong. He may not be cognizant of the error; however, other more skillful botanists 
will find him out. But if the cryptanalyst makes a mistake in observation or deduction, he fails to get any 
“answer” at all; he needs nobody to tell him he has failed. Further, there is one additional important point of 
difference. The botanist is studying a bit of Nature—and she does not consciously interpose obstacles, pitfalls, 
and dissimulations in the path of those trying to solve her mysteries. The cryptanalyst, on the other hand, is 
studying a piece of writing prepared with the express purpose of preventing its being read by any persons for 
whom it is not intended. The obstacles, pitfalls, and dissimulations are here consciously interposed by the one 
who cryptographed the message. These, of course, are what make cryptanalysis different and difficult. 


JL 




m 


to test thtem one by one, in a successive ch^.' He encounters many blind aJleys and dead-end 
streets, which force him to retrswie his steps; he makes many detours and jumps many hurdles. 
Some of these retracings of steps, doubling back on his tracks, jumping of hurdles, and detours 
are unavoidable, but a few are avoidable. If properiy employed, the analytical key will help 
the careful student to avoid those which should and can be avoided; if it does that much it will 
serve the principal purpose for which it is intended. 

e. The analytical key may, however, serve another purpose of a somewhat different nature. 
When a multitude of crypti^^phic systems of diverse types must be filed in some systematic 
manner apart from the names of the correspondents or other reference data, or if m conducting 
instructional activities classificatory designations are desirable, the reference numbers on the 
analytical key may be made to serve as “type numbers." Thus, instead of stating that a given 
cryptogram is a keyword-systematically-mixed-uniliteral-monoalphabetic-monographic substitu¬ 
tion cipher one may say that it is a “Type 901 cryptogram.” 

/. The method of assignii^ type numbers is quite simple. If the student will examine the 
numbers he will note that successive levels in the dichotomy are designated by successive hun¬ 
dreds. Thus, the first level, the classification into cipher and code is assigned the numbers 101 
and 102. On the second level, vmder cipher, the clas^cation into monographic and polygraphic 
systems is assigned the numb^ 201 and 202, etc. Numbers in the same hrmdreds apply 
therefore to systems at the same level in the classification. There is no particular virtue in thm 
scheme of assigning type numbers except that it provides for a considerable degree of expanaon 
in future studies. 





APPENDIX 1 

( 106 ) 





APPENDIX 

Table No. 

1-A. Absolute frequencies of letters appearing in five sets of Government plain-text telegrams, each set 

containing 10,000 letters. Arranged alphabetically_ 

1-B. Absolute frequencies of letters appearing in five sets of Government plain-text telegrams, each set 
containing 10,000 letters. Arranged according to frequency_ 

1- C. AbMlute frequencies of vowels, high frequency consonants, medium frequency consonants, and low 

frequency consonants appearing in five sets of Government plain-text telegrams, each set con¬ 
taining 10,000 letters_ 

2- A. Absolute frequency of letters appearing in the combined five sets of messages totalling 60,000 

letters. Arranged alphabetically_ 

2-B. Absolute frequency of letters appearing in the combined five sets of messages totalling 60,000 

letters. Arranged according to frequency- 

2-C. Absolute frequency of vowels, high frequency consonants, medium frequency consonants, and low 

frequency consonants appearing in the combined five sets of messages totalling 60,000 letters_ 

2-D. Absolute frequencies of letters as initial letters of 10,000 words found in Government plain-text tele¬ 
grams. (1) Arranged alphabetically, and (2) according to absolute frequencies_ 

2-E. Absolute frequencies of letters as finAl letters of 10,000 words found in Government plain-text tele¬ 
grams. (1) Arranged alphabetically, and (2) according to absolute frequencies_ 

3. Relative frequencies of letters appearing in 1,000 letters based upon Table 2. (1) Arranged alpha¬ 

betically, (2) according to absolute frequency, (3) vowels, (4) high frequency consonants, (6) med¬ 
ium frequency consonants, and (6) low frequency consonants_ 

4. Frequency distribution for 10,000 letters of literary English. (1) Arranged alphabetically, and 

(2) according to absolute frequencies_ 

6. Frequency distribution for 10,000 letters of telegraphic English. (1) Arranged alphabetically, and 

(2) according to absolute frequencies___ 

6. Frequency distribution of digraphs, based on 60,000 letters of Government plain-text telegrams, 

reduced to 6,000 digraphs- 

7-A. The 438 different digraphs of Table 6. Arranged according to their absolute frequencies_ 

7-B. The 18 digraphs composing 26% of the digraphs in Table 6. Arranged alphabetically according to 
their initial letters, (1) and according to their final letters (2) and according to their absolute 

frequencies___ 

7-C. The 63 digraphs composing 60% of the digraphs in Table 6. Arranged alphabeticaUy according to 
their initial letters, (1) and according to their final letters (2) and according to their absolute 

frequencies_ 

7-D. The 117 digraphs composing 76 % of the digraphs in Table 6. Arranged alphabetically according to 
their initial letters, (1) and according to their final letters (2) and according to their absolute fre¬ 
quencies__ 

7-E. All the 438 digraphs of Table 6. Arranged first alphabetically according to their initial letters and 

then alphabetically according to their final letters_____ 

(See Table 6. Read across the rows)_____ 

8. The 438 different digraphs of Table 6. Arranged first alphabetically according to their initial 

letters, and then according to their absolute frequencies under each initial letter_ 

9-A. The 438 different digraphs of Table 6. Arranged first alphabeticaUy according to their final letters 

and then according to their absolute frequencies_ 

9-B. The 18 digraphs composing 25 % of the 5,000 digraphs of Table 6. Arranged alphabetically according 
to their final letters, (1) and according to their initial letters, (2) and according to their absolute 

frequencies______ 

9-C. The 53 digraphs composing 50 % of the 5,000 digraphs of Table 6. Arranged alphabetically according 
to their final letters, (1) and according to their initial letters, (2) and according to their absolute 

frequencies...... 

9-D. The 117 digraphs composing 75% of the 5,000 digraphs of Table 6. Arranged alphabetically accord¬ 
ing to their final letters, (1) and according to their initial letters, (2) and according to their 

absolute frequencies____ 

9-E. AU the 438 different digraphs of Table 6. Arranged alphabeticaUy first according to their final letters 

and then according to their initial letters--- 

(See Table 6. Read down the columns)_ 


( 107 ) 






























108 


109 


Table No. 

10- The 56 trigraphs appearing 100 or more times in the 50,000 letters of government plain-text tele¬ 

grams— 

-A. Arranged according to their absolute frequencies- 

-B. Arranged first alphabetically according to their initial letters and then according to their absolute 

frequencies- 

-C. Arranged first alphabetically according to their central letters and then according to their absolute 

frequencies- 

-D. Arranged first alphabetically according to their final letters and then according to their absolute 
frequencies.. 

11- The 64 tetragraphs appearing 50 or more times in the 60,000 letters of government plain-text 

telegrams— 

-A. Arranged according to their absolute frequencies- 

-B. Arranged first alphabetically according to their initial letters and then according to their absolute 

frequencies--- 

-C. Arranged first alphabetically according to their second letters and then according to their absolute 

frequencies- 

-D. Arranged first alphabetically according to their third letters and then according to their absolute 

frequencies___ 

-E. Arranged first alphabetically according to their final letters and then according to their absolute 

frequencies----- 

12. Average and mean lengths of words--- 


129 

130 

130 

131 

132 

132 

133 

133 

134 
136 


Tabljs X-A^—Akiolviijreqvsneies qf letters appearing injm sets of Oovemmenial plaintext telegrams, 
each set containing 10,000 letters, arranged alphabeUcaUy 


Set No. 1 

Set No. 2 

Set No. 3 

Set No. 4 

set No. s 

Letter 

Absolute 

Frequency 

Letter 

Absolute 

Frequency 

Letter 

Absolute 

Frequency 

Letter 

Absolute 

Fluency 

Letter 

Absolute 

Frequency 





A 

6S1 

A 

740 

A_ 

741 





R 

98 

B . 

83 

B..„ 

99 





V. 

288 

C._. 

326 

C 

301 




413 

D 

423 

D... 

451 

D 

448 




1, 294 

R 

1, 292 

R 

1,270 

B_ 

1, 275 




287 

P_ 

308 

F-..-. 

287 


281 



G 

176 

G 

161 

G 

167 

G 

160 





H 

335 

H... . 

349 

H 

349 



T 

750 

I _ 

787 

I_ _. 

700 


697 





.1 

10 

J_ 

21 

.T 

16 




38 

K 

22 

K_ 

21 

K_ 

31 




393 

T. 

333 

T. 

386 

L_ 

344 




240 

H ... 

238 

M 

249 


268 

N 

786 

N._ 

794 

N 

815 

N 

800 

N 

780 

n 

686 

n 

770 

0 

791 

0.. 

766 

0_ 

762 

P 

241 

p 

272 

p 

317 

P_ 

246 


260 

q 

40 

Q 

22 

q 

45 

q___ 

38 

0- 

30 

R 

760 

R 

745 

R 

762 

R 

735 

R_ J 

786 

s 

658 

.q 

583 

.q 

585 

.q 

628 

.q 

604 

T,_ 

936 

T 

879 

T 

894 

T 

958 

T 

928 

U 

270 

ii 

233 

U._ 

312 

ir 

247 

U. J 

238 

V._ 

163 

V._ 

173 

V _ 

142 

V.. 

133 


165 

w 

166 

n 

163 

w 

136 

w 

133 

w 

182 

Y 

43 

X 

50 

X 

44 

X. 

53 

X 

41 

Y 

191 

Y 

166 

Y 

179 

Y... 

213 

Y 

229 

z. „ 

14 

7 

17 

z. . 

2 

7 

11 

Z_ 

6 

Total 

10,000 


10,000 


10,000 


10,000 


10,000 







Table 2-A .—Absolvie frequencies of letters appearing in the combined five sets of messages totalling 
BOfiOO letters, arranged alphabetically 


A-_ 

3, 683 

G._ 

819 

L._ 1, 821 

0- 

175 

V.... 

766 

B_ 

487 

H._ 

1, 694 

M lj5!.q7 

R. 

3, 788 

W 

780 

C._ 

1, 634 

I._ 

3,676 

N._ 3 ’975 

S._ 

3, 058 

XL... 

_ 231 

D...... 

2, 122 

J_ 

82 

0_ 3,764 

T...... 

4, 696 

y.... 

_ 967 

E._ 

6,498 

K._ 

148 

P._ 1,335 

u 

1, 300 

7 

49 

F._ 

1,416 








Table 1-B. —Absolvie frequencies of letters appearing in Jive sets of Government plain-text telegrams, 
each set containing 10,000 Utters, arranged according to frequency 


Set No. 1 

1 eetNo.a 

1 Set No. S 

II Bet No. 4 

II Set No. S 

Letter 

Absolute 

Frequency 

Letter 

Absolute 

Frequency 

Letter 

Absolute 

Frequenoy 

Letter 

Absolute 

Frequency 

Letter 

Absolute 

Frequenoy 

R 

1, 367 

E._ _ 

1, 294 

E 


R 




T 

936 

T.. 

879 

T 

894 

T 




N 

786 

N_ 


N 






R. 

760 

A _ 


0 





7sn 

T 

742 

0 ..... 

770 

T ...: . 






A 

738 

I _ 


R 






0. 

685 

R.. _ 

745 

A 






.q , 

658 

S— 

683 

a 






n 

387 

D... .. 

413 

D 






r. 

365 

L_ 

393 

H 






G 

319 

H.. 


I. 






H 

310 

C_ 

300 

P_ _J 


c 




II 

270 ' 

P_ 

287 

II 


p 




p 

253 

P.. 

272 

F.. 


M 




u 

242 

IL . .. 

240 

G 

288 

II 

247 

P 

260 

p 

241 

u 

233 

u 

238 

P_ 

245 

u 

238 

Y... 

191 

G 

176 

Y 

179 

Y 

213 

Y_ 

229 

G__ 

166 

V 

173 

G 

161 

G 

167 

W 

182 

■ 

166 

w. 

163 

V 

142 

V 

133 

V 

155 

V. 

163 

Y..._. 

155 

W 

136 

W 

133 

G 

160 

B 

104 

R 

103 

R 

98 

R 

S3 

R 

99 

X._ 

43 

X 

60 

q... 

45 

r._ 

53 

X 

41 

q . . 

40 

K ... 

38 

X 

44 

Q_ 

38 

K 


K_ 

36 

q_ 

22 

K 

22 

K._ 

21 

Q_ 

30 


18 

J_ 

17 

J_ 

10 

.1 

21 

.1 

16 

•L ! 

14 

z_ 

17 

7 . 

2 

7 

11 

7. 












Total_ 

10, 000 


10, 000 


10, 000 


10,000 


10,000 










148274—88-8 


i 



























































































110 


Table 1-C .—Absolute Jrequeincies of vowels, high frequency consonants, medium frequency con¬ 
sonants, and low frequency consonmds appearing in five sets of Oovemment plain-text tele¬ 
grams, each set containing 10,000 letters 



> Grand total, £0,000. 


Table 2-B .—Absolute frequencies of letters appearing in the combined five sets of messages totalling 
60,000 letters arranged according to frequencies 


E_ 

... 6,498 

I_ 

... 3,676 

C....... 

... 1,.534 

y._ 

. 967 

X._ 

231 

T. 

... 4, 596 

S...... 

... 3,058 

F.._ 

... 1,416 

G._ 

819 

0-_ 

175 

N....... 

... 3,976 

D....... 

... 2, 122 

P....... 

... 1,335 

w. 

. 780 

KL. 

148 

R-_ 

... 3,788 

L...... 

... 1,821 

U_ 

... 1,300 

V_ 

. 766 

J_ 

82 

0 

... 3, 764 

H. 

... 1, 694 

M 

... 1, 237 

B 

487 

2L_ 

49 

A... 

... 3,683 










Table 2-C .—Absolute frequencies of vowels, high frequency consonants, medium frequency con¬ 
sonants, and low frequency consonants appearing in the combined five sets of messages totalling 
60,000 letters 


Vowels................ 19,888 

High Frequency Consonants (D, N, R, S, end T)_____ 17,538 

Medium Frequency Consonants (B, C, F, G, H, L, M, P, V, and W)___ 11,889 

Low Frequency Consonants (J, K, Q, X, and Z)____ 685 

Total.......... 50,000 



111 


Table 2-D. —Absolute frequencies of letters as initial letters of 10,000 words found in Oovemment 
plaintext telegrams 

(1) ARRANGED ALPHABETICALLY 


A. 905 G. 109 L__ 196 . 30 V..... 77 


B 

287 

H 

272 

M 

384 

- 

R.. 

611 


320 

C_ 

664 

I_ 

344 

N. 

441 

S.. 

965 

X.._ 

4 

D.. 

525 

J. 

44 

0 . 

646 

T.. 

.. 1,253 

Y_ 

88 

E. 

.. 390 

K-.. 

23 

P. 

433 

U.. 

122 

Z. 

12 

F.. 

.. 865 

















Total... 

.. 10,000 


(2) 

ARRANGED ACCORDING 

TO ABSOLUTE FREQUENCIES 


T... 

. 1,253 

R-_ 

611 

M.. 

384 

L.. 

196 

J_ 

44 

S. 

965 

D_ 

525 

I. 

344 

U... 

122 

Q. 

30 

A. 

905 

N._ 

441 

W_ 

320 

G.. 

109 

K........ 

23 

F. 

855 

P. 

433 

B.. 

287 

Y. 

88 

Z. 

12 

C.. 

664 

E-.. 

.. 390 

H.. 

272 

V.... 

77 

X . 

4 


0. 646 _ 

Total... 10,000 

Table 2-E .—Absolute frequencies of letters as final letters of 10,000 words found in Government 
plain-text telegrams 

(1) ARRANGED ALPHABETICALLY 

A. 269 G.. 225 L._ 354 Q- 8 V... 4 

B. 22 H... 450 M. 154 R._ 769 W.. 45 

C_ 86 I_ 22 N. 872 S. 962 X._ 116 

D._ 1,002 J_ 6 0.. 575 T. 1,007 Y_ 866 

E_ 1,628 K._ 53 P...... 213 U_ 31 Z- 9 

F._ 252 - 

Total-..- 10,000 


(2) ARRANGED ACCORDING TO ABSOLUTE FREQUENCIES 


R 

1, 628 

R 

769 

F. 

252 

C.. 

86 

I... 

22 

T_ 

.. 1,007 

0. 

575 

G. 

226 

K.. 

53 

Z_ 

9 

D.. 

.. 1,002 

H.. 

450 

P. 

213 

W.. 

45 

0-. 

8 

S. 

962 

L. 

. 364 

M. 

154 

u. 

31 

J_ 

6 

N 

872 

A_ 

269 

X .. . 

116 

B. 

22 

V. 

4 

Y....... 

.. 866 










Total.— 10,000 









































































































































05 d <i 


112 


Table 3. —Belaiwefrequenciea oj letters appearing in 1,000 letters based upon Table 2-B 

(1) ARRANGED ALPHABETICALLY 


A._ 73.66 G_ 16.38 L._ 36.42 Q_ 

B_ 9.74 H_ 33.88 IL_ 24.74 R._ 

C-_ 30. 68 I_ 73. 52 N._ 79.50 S„_ 

D_ 42.44 J_ 1.64 0_ 75.28 T.._ 

E. _ 129.96 K._ 2.96 P._ 26.70 U._ 

F. _ 28. 32 


3.50 V._ 15.32 

75. 76 W. _ 15. 60 

61.16 X-_ 4.62 

91.90 Y._ 19.34 

26.00 Z._ .98 

Total.... 1,000.00 


(2) ARRANGED ACCORDING TO FREQUENCY 

E _ 129. 96 I_ 73.52 C_ 30. 68 Y._ 19. 34 X._ 4. 62 

T_ 91. 90 S_ 61. 16 F._ 28. 32 G._ 16. 38 Q._ 3.50 

N_ 79. 50 D._ 42.44 P._ 26. 70 W._ 15. 60 K._ 2. 96 

_ 75.76 L....._ 36.42 U._ 26.00 V._ 15.32 J_ 1.64 

_ 75.28 a_ 33.88 BIL_ 24.74 B_ 9.74 Z._ .98 

_ 73.66 


(3) VOWELS 


A_ 73. 66 

E_ 129.96 

I_ 73. 52 

0_ 75.28 

U_ 26. 00 

Y_ 19. 34 

Total _ 397.76 

(4) HIGH-FREQUENCY 
CONSONANTS 

D___ 42. 44 

N_ 79. 50 

R_ 75. 76 

S_ 61. 16 

T_ 91.90 


(5) MEDIUM-FREQUENCY 
CONSONANTS 


B_ 9.74 

C.. 30. 68 

F.__ 28.32 

G_ 16. 38 

H..._ 33. 88 

L_ 36. 42 

M_ 24. 74 

P_ 26. 70 

V_ 15. 32 

W_ 15. 60 

Total _ 237.78 


Total_ l,0d0.00 

(6) LOW-FREQUENCY 
CONSONANTS 


X_ 4.62 

Q_ 3. 50 

K_ 2.96 

J_ 1.64 

Z_ .98 

Total_ 18.70 

Total (3), (4), 

(5), (6)_ 1,000.00 


Total- 


350. 76 
















































































H3 


—Fregu&ncy distrikuHon Jar 10,000 Utters oj hierary English, as compiled by Hilt ‘ 
(1) ALPHABETICALLY ARRANGED 


A. _ 

778 

G . 

174 

L._ 

372 

Q.- 

8 

V._ 

112 

B... 

141 

H... . . 

595 

M._ 

288 

R 

651 

w 

176 

C. 

296 

I. 

667 

N.. 

686 

S 

622 

X 

27 

D.. 

402 

J_ 

51 

0_ 

807 

T._ 

855 

y_ 

196 

E_ 

1, 277 

KL__ 

74 

P-_ 

223 

n. _ 

308 

ZL_ . 

17 

F._ 

197 

1, 277 

(2) ARRANGED ACCORDING TO 

R_ 6.«51 U_ SOS 

FREQUENCY 

Y_ 19fi 

K... 

74 

T_ 

855 

S 

622 

c. 

296 

W 

176 

J. 

51 

0_ 

807 

H.__ 

595 

M._ 

288 

G._ 

174 

X._ 

27 

A_ 

778 

D 

402 

P 

223 

R 

141 

z._ 

17 

N._ 

686 

T. 

372 

F 

197 

V 

112 

0— 

8 

I_ 

667 







—Freque'Mfy distrUviion Jor 10,000 letters ej telegraphic English as compiled by Hitt 
(1) ALPHABETICALLY ARRANGED 


A. _ 

813 

G. 

__ 201 

L. _ 

392 

Q. - 

38 

V. _ 

136 

B _ 

149 

H. 

. 386 

M. _ 

273 

R. . 

677 

w. _ 

166 

C_ 

306 

I. 

__ 711 

_ 

718 

S- .. . 

656 

X. _ 

51 

D. _ 

417 

J. 

—42 


844 

T _ 

634 

y. _ 

208 

E. . 

1, 319 

K.. 

... . 88 

P __ 

243 

U_ _ 

321 

z 

6 

F. _ 

E. _ 

205 

1, 319 

S- 

(2) ARRANGED ACCORDING TO FREQUENCY 

_ 6.56 U_ 321 F ._ 20,5 

K 

88 

0 _ 

844 

T.. 

634 

C. 

306 

G 

201 

X 

51 

A. _ 

813 

D.. 

_ 417 

M... .. 

273 

W _ 

166 


42 

N. _ 

718 

L.. 

- 392 

P _ ... 

243 

B- . 

149 

0 _ 

38 

I _ 

711 

H.. 

386 

y... - 

208 

V . 

136 

Z. _ 

6 

R- _ 

677 








* Hitt, Capt. Parker. Manual for the Solution of Military Ciphers. Army Service Schools Press, Fort 
Leavenworth, Kansas, 1916. 




























































their ahsolvte frequent 


114 


Table 7-A .—The IfiS dijfferent digraphs oj table 6 arranged according to their absolute frequencies 


EN... Ill 

RE_ 98 

ER._._ 87 

NT_ 82 

TH-_ 78 

ON-...._ 77 

IN-_ 75 

TE..... 71 

AN._ 64 

OR._ 64 

ST_ 63 

ED._ 60 

NE._ 57 

VE_ 57 

ES_ 54 

ND..._...... 62 

TO._ 60 

SE_ 49 


_ *1, 249 

AT_ 47 

TI_ 45 

AR. 44 

EE. 42 

RT_ 42 

AS. 41 

CO. 41 

10_ 41 

TY._ 41 

FO_ 40 

FI__ 39 

RA_ 39 

ET.. 37 

OU.... 37 

LE.. 37 

MA...... 36 

TW... 36 

EA. 35 

IS.-. 35 

SI. 34 

DE. 33 

HI-.... 33 

AL. 32 

CE. 32 

DA_ 32 


EC_ 32 

RS_ 31 

UR. 31 

NI. 30 

RI. 30 

EL. 29 

HT._ 28 

LA._ 28 

RO. 28 

TA_ 28 


_ »2. 495 

LL._ 27 

AD._ 27 

DI_ 27 

El_ 27 

IR._ 27 

IT_ 27 

NG._ 27 

ME.- 26 

NA_ 26 

SR_ 26 

IV_ 25 

OF._ 25 

OM.. 25 

OP._ 25 

NS_ 24 

SA.- 24 

IL__ 23 

PE... 23 

IC_ 22 

WE_ 22 

UN_ 21 

CA. 20 

EP...-. 20 

EV_ 20 

GH. 20 

HA. 20 

HE. 20 

HO. 20 

LI. 20 

SS... 19 

TT.. 19 

IG...-. 19 

NC_ 19 


OL_ 19 

OT—-- 19 

TS_ 19 

WO__ 19 

BE- 18 

EF... 18 

NO_ 18 

PR- 18 

AI_ 17 

HR._ 17 

PO_ 17 

RD._ 17 

TR._ 17 

DO.. 16 

DT._ 15 

IX._ 16 

QU.- 15 

SO- 15 

YT_ 16 

AC_ 14 

AM.. 14 

CR_ 14 

CT_ 14 

EM.. 14 

GE. 14 

OS...... 14 

PA. 14 

PL._ 13 

RP_ 13 

SC. 13 

WI. 13 

MM._ 13 

DS. 13 

AU_ 13 

IE. 13 

LO. 13 


_ *3,745 

AP.... 12 

DR.... 12 

EQ-. 12 

AY...... 12 

EO... 12 

OD.. 12 

SF.- 12 


US_ 12 

UT_ 12 

VI_ 12 

WA._ 12 

FF-_ 11 

PP_ 11 

RR_ 11 

UE._ 11 

FT._ 11 

SU-__ 11 

YF._ 11 

YS._ 11 

YO._ 10 

FE-_ 10 

IF._ 10 

LY_ 10 

MO_ 10 

SP_ 10 

YE.. 9 

FR.. 9 

IM._ 9 

LD._ 9 

MI_ 9 

NF. 9 

RC_ 9 

RM._ 9 

RY_ 9 

DD. _ 8 

NN._ 8 

DF__ 8 

lA._ 8 

HU._ 8 

LT._ 8 

MP... 8 

OC._ 8 

OW._ 8 

PT._8 

UG..... 8 

AV.. 7 

BY. . 7 

Cl_ 7 

ER.. 7 

OA._ 7 

EW._ 7 

EX_ 7 


1 The 18 digraphs above this line oompose 25% of the total. 

• The 53 digraphs above this line compose 60% of the total, 

* The 117 digraphs above this line pompose 75% of tl^ total, 


1 


I 

I 

I 


115 

Table l-k—The 4S8 different digraphs of table 6 arranged according to 
cies —Contmued 


GA_ 

/ 

SR_ 

5 

AA_ 

3 

LM._ 

LR._ 



TL._ 

TU 

5 

5 

EU. . 

3 



OE.... 

3 

LU._ 


7 

IIM 

5 

YI_ 

FS_ 

3 

3 

LV-_ 



AV 

4 

LW._ 


7 

BA _ 

4 

FU._ 

3 

MR-. 

MT._ 



RQ 

4 

4 

GN._ 

3 

XT.-. 

AB. 

AG 

BL—. 

00 

YA. 

GO 

ID 

KE 

LS 

MB . 

PI 

PS - 

7 

6 

6 

6 

6 

6 

6 

6 

6 

6 

6 

6 

6 


GS_ 

3 

MU._ 


4 

HC 

3 

3 

MY._ 


4 

HN 

NB._ 

DB..-. 

4 

4 

LB. 

1.0 

3 

3 

NK._ 

OG_ 


4 

T.P 

3 

OK._ 


4 

LP.. 

3 

PF._ 


4 

MO 

3 

RB_ 



NP 

3 

SG_ 


4 

MV 

3 

SL._ 


4 

NW 

3 

TP._ 



OR _ 

3 

UP. 


4 

AH 

2 

WN._ 

NH 

4 

AK._ 

2 

XA_ 



NR 

4 

BI. 

2 

XC_ 


g 

OR 

4 

BR... 

2 

XI_ 

. 

g 

PM 

4 

BU.. 

2 

XP_ 

m - 

g 

RW 

4 

DG. 

2 

YB_ 

v^ 

g 


4 

DR_ 

2 

YL._ 

VfJ 

g 

sw . 

4 

DO. 

2 

YM._ 

P-T. 

6 

WH. 

4 

AO. 

2 

ZE_ 

DU _ 

5 

vn 

4 

OY.. 

2 

GG._ 


6 

vn 

4 

FC__ 

2 

AJ_ 

■■ 

5 

YP 

4 

FL.. 

2 

BJ_ 

01 _ 



3 

no 

2 

BM._ 


__ 

3 

GF..—.. 

2 

BS_ 

UA- 

^IT 

0 

5 

RH 

3 

GL. 

2 

BT._ 


5 

SB_ 

3 

GP.. 

2 

CD_ 

F^ 

5 


3 

GU........ 

2 

CF_ 

GR. 

5 

TB. 

3 

HD. 

2 

CM._ 

HF. 


TTR 

3 

HM 

2 

CN_ 


Tin 

3 

TR 

2 

CS_ 

NL—..- 

5 

5 

im 

3 

IK.... 

2 

CW_ 

MV 

5 

YP 

3 

IZ. 

2 

CY_ 

RT 


nn 

3 

JE_ 

2 

DJ_ 

RL - 


AW 

3 

JO. 

2 

DY_ 

RV....- 

5 

DL_ 

3 

JU._ 

2 

EJ_ 



2 

2 

2 

2 

2 

2 

2 

2 

2 

2 

2 

2 


2 

2 

2 


2 

2 

2 

2 

2 

2 

2 

2 

2 

2 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 

1 













































































































































































































































































































































Table 7-A.-*-?%c 08 different digraphs ff table 6 arranged according ie their ahsohite frequen^ 
dee —Continued 


AK.. 

1 

HV 

1 

PD 

1 

WI. 


UO_ 

1 

JA 

1 

PN... 


WR 


YU.. 

1 

KA... ... 

1 

PV.. 

j 

WR 


E2. _ 

1 

KC_ _ 


PW 


WY 


FD . 


KL . 

1 

PY._ 


YD 


FG._ 

j 

KN_ 


QM 

j 

YE 


1 FIL_ 

1 

KS 

J 

QR . 

1 

YF 


FP._ 

1 

LG._ 

1 

RJ _ 


YH 


FW._ 

1 

LH._ 

1 

RK._ 

J 

YH 


FY._ 

1 

LN._ 

1 

SK 

J 

xo _ 


GD_ 

1 

MD 

1 

sv. _ 

1 

XR_ 


GJ....._ 

1 

MF._ 

1 

SY._ 

1 

xs _ 


GM.__ 

j 

MR._ 

1 

TC 

1 

YG_ 


GW._ 

1 

NJ_ 

1 

TQ.- 

1 

YH._ 


HB- 

1 

NP_ 

1 

rr. 

1 

YW._ 


HL™. _ 


OJ_ 


UP 

I 

Zh _ 


HP.__ 

1 

OX.__ 

1 

IIV 

1 

7.1 


Hp 

1 

PR 

1 

VO 

1 



1 HI._ 

1 

PC_ 

1 

VT._ 

1 

Total_ 

5.000 


Table 7-B.— The 18 digraphs composing 86% oj the digraphs in Table 6 arranged alphabetieaUg 
according to their initial letters 


(1) AND ACCORDING TO THEIR FINAL (2) AND ACCORDING TO THEIR ABSOLUTE 

LETTERS FREQUENCIES 


AN 

64 

ON._ 

77 

AN 

64 

ON 




OR._ 

64 



OR._ 

64 

ED-_ 

60 

RE._ 

98 

EN 

111 

RE 


EN._ 

111 



ER._ 

87 



ER_ 

87 

SEL_ 

49 

ED 

60 

RE 


RS 

54 

ST_ 

63 

ES_ 

54 

ST... 

63 



TE._ 

71 



TH-_ 

78 

IN..._ .... 

75 

TH._ 

78 

TN 

75 


71 



TO_ 

50 



TO_ 

50 

ND_ 

52 

VE._ 

57 

NT. 

82 

VE_ 

57 

NE._ 

57 



NE 

57 



NT._ 

82 

Total.. 

..... 1,249 

NP-- 

62 

Total... 

... 1,249 


117 


Table 7-C .—The 6S digraphs eompoeing 60%of Me 6,000digraphs ej Tedle 0, amanged alphaie^Ccdlg 
according to their vnitud letters 


(1) AND ACCORDING TO THEIR PINAL (2> ANI> ACCORDING TO THEIR ABSOLUTE 

LETTERS FREQUENCIES 


AT. . 

32 

MA 

36 

AN 

64 

MA 

36 

AN_ 

64 



AT._ 

47 



AR 

44 

ND._. 

52 

AR 

44 

NT 

82 

AS._ 

41 

NE._ 

67 

AS__ 

0 

m. _ 

57 

AT._ 

47 

NT 

30 

AT. 

32 

MP... 

52 



NT._ 

82 



NI_ 

30 

CEL-. 

32 



CO.__ 

41 



no 

41 

ON 

77 

f!E 

32 

m 

77 



OR_ 

64 



OR._ 

64 

DA 

32 

OU _ 

37 



OU 

37 

DEL. 

38 



DA_ 

32 





RA._ 

39 



RE._ 

98 

EA_ 

36 

RE_ 

98 


111 

RT._ 

42 

EC-. 

32 

RI_ 

30 

RP 

87 

RA_ 

39 

ED 

60 

RO._ 

28 



RS._ 

31 

raE 

42 

RSl. 

31 

ro. 

c? 

RI . 

30 

ET. 

29 

RT _ 

42 

-- 

RR 

54 

42 

RO._ 

28 

EN _ 

111 



ET._ 

37 



ER 

87 

SE-.- 

49 



ST. _ 

63 

E.R 

64 

SI . 

34 


32 

SEL. 

49 

ET ... 

37 

ST-. 

63 

EL_ 

20 

SI-_ 

34 


FI._ 39 

FO-_ 40 

HI._ 33 

_ 28 

IM._ 76 

10._ 41 

IS_ 36 

U- 28 

LE.- 37 


TA_ 28 

TE._ 71 

TH._ 78 

TI_ 46 

TO._ 60 

TW._ 30 

TY._ 41 

UR._ 31 

VE._ 57 

Total. 2,496 


FO._ 

FI_ 

HI._ 

HT._ 


IN¬ 

TO. 

IS. 


LEL. 

LA.. 


40 
39 

33 

28 

75 

41 

36 

37 
28 


m_ 78 

TEL_ ' 71 

TO-_ 50 

TI._ 46 

TY._ 41 

TW-_ 36 

TA_ 28 

UR-_ 31 

VE._ 57 

Total. 2,495 





















































































































































118 


119 


AC. ... 

AD. ... 

AI 

AL 

AM 

AN 

AR.... 

AS 

AT 

AU.... 


CA... 

CE... 

CH... 

CO... 

CT... 


DA... 

DE... 

DI... 

DO... 

DS. .. 

DT. .. 


EA.... 

EC.... 


El.... 

EL. ... 

EM. ... 

EN. ... 


—The 117 digraphs composing 75% of the 6,000 digraphs oj Table 6, arranged alpha¬ 
betically OMording to their initial letters - 

(1) AND ACCORDING TO THEIR FINAL LETTERS 


27 

17 

32 

14 

64 

44 

41 

47 

13 


20 

32 

14 

41 

14 

32 

33 
27 
16 
18 

15 

36 

32 

60 

42 
18 
27 
29 
14 

111 



Table 7-D, Concluded.—77i« 117 digraphs comprising 75% oJ the 5,000 digraphs of Table 6, 
arranged alphabetically according to their initial letters - 



(2) AND ACCORDING TO THEIR ABSOLUTE FREQUENCIES 


AN. . . 

64 

El.. . 

27 

MA.... 

36 

RI_ 

30 

AT 

47 

EP... . 

20 

ME. . 

26 

RO. . 

28 

AR. 

44 

EV... . 

20 



RD.... . 

17 

AS_ 

41 

EF. 

18 

NT_ 

82 



AL.. 

32 

EM_ 

14 



ST 

63 

AD_ 

27 



ND_ 

52 

SE. . 

49 

AI .. 

17 

FO....- . 

40 

NI .. 

30 

SI _ 

34 

AC . 

14 

FI _ 

39 



SH 

26 

AM 

14 





SA 

24 

AU 

13 

GH .. 

20 



SS 

19 



GE . 

14 

NC .. 

19 

SO... . 

15 

BE 

18 



NO.... .. 

18 





HI .. 

33 



TH 

78 

CO . 

41 

HT....: . 

28 

ON .. 

77 

TE .. 

71 

CE . 

32 



OR. .. 

64 

TO 

60 

CA.... . 

20 

HO 

20 

OU .. 

37 

TI 

45 

CH._ 

14 

HR.. 

17 

OF . 

25 

TY 

41 

CT._ 

14 

OM . 

26 

TW . 

36 



TN 

75 

OP . 

25 

TA . 

28 

DE 

33 



OL . 

19 

TS 

19 

DA _ 

32 

T.«; 

35 

OT . 

19 

TT . 

19 

DI _ 

27 

IR. . 

27 

OS . 

14 

TR. . 

17 

DO . 

16 

IT . 

27 





DT . 

15 

IV 

25 

PR 

23 

UR . 

31 

DS _ 

13 

TT. 

23 

PR 

18 

UN. _ 

21 



IC _ 

22 

PO _ 

17 



EN 

111 

IG . 

19 

PA 

14 

VE 

57 

ER _ 

87 

IX . 

15 





ED _ 

ES. __ 

60 

54 

IE . 

13 

QU . 

15 

WE . 

WO . 

22 

19 

EE _ 

42 

LE . 

37 




ET . 

37 

LA. . 

28 

RE- . 

98 



EA _ 

EC 

35 

32 

LL .. 

1.1 

27 

20 

RT .- 

RA . 

42 

39 

YT.. . 

15 

EL . 

29 

LO. __ 

13 

RS . 

31 

Total.. 

... 3, 745 


Table 7-E.—ylM the 438 digraphs of Table 6, arranged first alphabetically according to their initial 
letters and then alphabetically according to their final letters. 

(SEE TABLE 6.—READ ACROSS THE ROWS) 





























































































































































































































120 


121 


1 


Table 8, —The 4S8 different digraphs oj Table 6, arranged first alpkabetieaUy according to their 



initial letters, and 

then according to their absolute fregncncies under each initial letter ‘ 


AN.... 


64 

CT . 

14 ED... 

60 

GH 

20 

AT.... 


47 

Cl.. 

7 RS 

54 

GR 

14 

AR. 


44 

rrr. 

a RE 

42 

GA 

7 

AS.... 


41 

RK 

4 ET_ 

37 

GO 

6 

AL.... 


32 

CR._ 

4 EA_ 

35 

GI_ 

5 

AD... 


27 

CU_ 

4 EC_ 

32 

GR 

5 

AI.... 


17 

CC_ 

3 EL_ 

29 

GT._ 

4 

AC.... 


14 

CD _ 

1 El. 

27 

GN._ 

3 

AJIL.. 


14 

OF_ 

1 EP_ 

20 

GS._ 

3 

AU _ 


13 

CM 

1 EV.. 

20 

GR 

2 

AP 


12 

RN 

1 EF.. 

18 

GF 

2 

AY . 


12 

RS 

1 EM.. 

14 

GT. 

2 

AV 


7 

RW 

1 EO. 

12 

GP 

2 

AB 


6 

RY 

1 RQ 

12 

GO 

2 

AG.... 


6 


EH 

7 

GP 


Af" 


4 

PE. 

33 EW._ 

7 

GG 

1 

AA. 


3 

DA.. 

32 RX 

7 

G.T 

1 

AW.... 


3 

PI 

27 EB_ 

4 

GM._ 

1 

AH.... 


2 

DO 

16 EG 

4 

GW 

1 

AK.... 


2 

DT-. 

Mi RY 

4 



A0._. 


2 

ns 

13 EU._ 

3 



AE.... 


1 

dr._ 

12 EJ_ 

1 



AJ.... 


1 

DP 

8 EZ 

1 

HT 

33 




DF._ 

8 


HT-_ 

28 

RR 


18 

DIL_ 

.<5 RO 

40 

HA_ 

20 

BY.... 


7 

PP 

R FI 

39 

HR 

20 

RT. 


6 

no 

K FF 

11 

HO 

20 

RA 


4 

m. _ 

4 FT..... 

11 

HR._ 

17 

BO.... 


4 

DC._ 

4 FR 

10 

HU._ 

8 

BI.... 


2 

PN 

4 FR._ 

9 

HF_ 

5 

BR_ 


2 

PW 

4 FA_ 

5 

HR 

4 

BU.... 


2 

nr. 

3 FS_ 

3 

HR 

3 

BJ_ 


1 

DV._ 

3 FU._ 

3 

HN._ 

3 

BM_ 


1 

PR 

9 FR 

2 

Hn 

2 

BS._- 


1 

nH 

9 FT. 

2 

HM._ 

2 

BT..... 


1 

DQ_ 

9 FD 

1 

HB_ 

1 




D.I 

1 FG_ 

1 

HL._ 

1 

CO 


41 

PY. 

1 FM . . . . 

1 

HP._ 


CE..... 


32 


FP.. 

1 

HQ.- 

1 

CA. 


20 

RN 

Ill FW._ 

1 

HW 


CH..... 


14 

ER._ 

87 FY._ 

1 

HY.. 

1 


• For arrangement alphabetically first under intial letters and then under final letters, see Table 6. 


Table 8, Contd.—The 4S8 different digraphs oj TabU 6, arranged first alphabetically according to 
their initial letters, and then according to their absolute jregvcndes under each initial letter ‘ 




T.T 

20 

NE_ 

57 

OA_ 

7 

TO 

41 

T.0 

13 

ND_ 

52 

OV_ 

7 

IS 

35 

I.Y 

10 

NI._ 

30 

00_ 

6 


27 

T.P 

9 

NG._ 

27 

01_ 

5 

IT_ 

27 

LT_ . 

8 

NA-_ 

26 

OB _ 

4 


25 

T.S 

6 

NS_ 

24 

OE_ 

3 

IL_ 

23 

LB_ 

3 

NC_ 

19 

OH_ 

3 



T.R 

3 

NO 

18 

OG._ 

2 



T.F 

3 

NF_ 

9 

OK._ 

2 

TX 

15 

T.P 

3 

NN_ 

8 

OY._ 

2 


13 

T.M 

2 

NU._ 

7 

OJ... 

1 


10 

LR. 

2 

NL_ 

5 

OX_ 

1 


9 

T.TI 

2 


5 




8 

T.V 

2 

NY._ 

5 

PE_ 

23 

IP_ 

7 

LW._ 

2 

NH._ 

4 

PR._ 

18 


6 

T.R 

1 

NR._ 

4 

PO_ 

17 



TO 

1 

NP 

3 

PA_ 

14 



T.N 

1 

NV 

3 

PL_ 

13 

IK. _ 

2 



NW-.... 

3 

PP_ 

11 

T7. 

2 

MA 

36 

NB_ 

2 

PT_ 

8 



MR_ 

26 

MK._ 

2 

PI. 

6 

■TR 

2 

MM 

13 

NJ_ 

1 

PS. 

6 

.TO 

2 

MO 

10 

NQ 

1 

PM.... 

4 

JU.. 

. 2 

MI_ 

9 



PH_ 

3 

■TA 

1 

MP 

8 

ON._ 

77 

PU.. 

3 



MB._ 

6 

OR 

64 

PF_ 

2 

KE_ 

6 

MS_ 

4 

OU._ 

37 

PB. 

1 

FT 

2 

MR 

3 

OF._ 

25 

PC. 

1 

ka_ 

1 

MR 

2 

OM._ 

25 

PD._ 

1 

Iff! 

1 

MT 

2 

OP 

25 

PN.. 

1 

KT. 

1 

MU._ 

2 

OL 

19 

PV_ 

1 

KN._ 

1 

MY 

2 

OT_ 

19 

PW_ 

1 

WR 

1 

Mn 

1 

OS_ 

■ 14 

PY_ 

1 



MF 

1 





T.R 

37 

MH 

1 

OD._ 

12 

QU._ 

15 

la_ 

28 



OR 

8 

QM_ 

1 

LL_ 

27 

NT._ 

82 

OW._ 

8 

OR- 

1 


* For arrangement alphabetically first under initial letters and then under final letters, see Table 6. 


I 







































































































































































































































































i2i 


Table 8, Concluded.— T%e 438 different digraphs off Table 6, arranged first alphabetically according 
to their initial letters, and then according to their absolvle ffrequencies under each initial letter ‘ 


RE 

98 

SR 

6 

US 

12 

XI 

2 

RT 

42 

SN.. 

4 

UT_ 

12 

XP. 

2 

RA 

39 

SW_ 

4 

UE.... 

11 

XD 

1 

R.S 

31 

SB.. 

3 

UG.... 

8 

XE 

1 

RT 

30 

SM... 

3 

UL_ 

6 

XF 

1 

Rfl 

28 

SR 

2 

UA 

5 

XH 

1 

RD 

17 

SL.. 

2 

UI.. 

5 

XN 

1 

RP 

13 

SK 

1 

UM.. 

5 

XO 

1 

RR 

11 

SV 

1 

UB. 

3 

XR 

1 

Rfi 

9 

SY 

1 

UC..... 

3 

XS 

1 

RM. 

9 



UD_ 

3 



RY 

9 

TH 

78 

UP... 

2 

YT... 

15 

RR 

7 

TR 

71 

UF_ 

1 

YF. 

11 

RN 

7 

TO 

50 

UO 

1 

YS. 

11 

RF 

6 

TI 

45 

UV . 

1 

YO... 

10 

RL 

5 

TY 

41 



YE.. 

9 

Rll 

6 

TW 

36 

VE . 

57 

YA. 

6 

RV 

5 

TA 

28 

VT 

12 

YN 

6 

HW_ 

4 

TS_ 

19 

VA.. 

6 

YC. 

4 

RH 

3 

TT_ 

19 

VO 

1 

YD_ 

4 

RB _ 

2 

TR 

17 

VT . 

1 

YR . 

4 

RJ_ 

1 

TF . 

7 



YI _ 

3 

RK. _ 

_ 1 

TN. _ 

7 

WR 

22 

YP ... 

3 



TC . 

6 

WO . 

19 

YB 

2 

RT 

63 

TD . 

6 

WI _ 

13 

YL . 

2 

SE .. 

49 

m . 

6 

WA 

12 

YM . 

2 

SI 

34 

TT.. 

5 

WH._ 

4 

YG 

1 

RH 

26 

TU . 

5 

WN 

2 

YR 

1 

RA 

24 

TB _ 

3 

WL. 

1 

YU 

1 

RR 

19 

TP 

2 

WR 

1 

YW 

1 

SO 

15 

TR 

1 

WS 

1 



RR 

13 

TQ 

1 

WY 

1 

ZE. . 

2 

RF 

12 

T7 

1 



ZA _ 

1 

.RTI 

11 



XT__ 

7 

ZI 

1 

SP-. 

10 

UR . 

31 

XA.. 

2 



SD... 

5 

UN. .. 

21 

xc.. . 

2 

Total.... 

.. 5,000 


' For arrangement alphabetically first under initial letters and then under final letters, see Table 6. 


123 


Table 9-A. —The 4S8 different digraphs off Table 6, arranged, first alphabetically according to their 
final letters, and then according to their absolute ffrequencies 





FR 

32 

RE.. 

98 

GF.. 

2 

MA. 


36 

IC.... 

22 

TE... 

71 

PF 

1 

EA.. 


35 

NC..- 

19 

NE. 

57 

CF 

2 

DA.. 


32 

AC...... 

14 

VE. 

57 

MF 

1 



28 

SC_ 

13 

SE.. 

49 

UF 

1 




RC 

9 

EE_ 

42 

XF 

1 

NA. 


26 

OC. 

8 

LE. 

37 



SA. 


24 

TC.... 

6 

DE_ 

33 







4 

RR 

32 

NG.. 

27 

HA 


20 

YC. 

4 

MR 

26 

IG. 

19 

PA_ 


14 

CC....- 

3 

PE. 

23 

UG 

8 




HC 

3 

WE.. 

22 

RG 

7 

lA. 


8 

LC__ 

3 

HE.... 

20 

AG 

6 

GA. 


7 

MC_ 

3 

BE. 

18 

EG 

4 

OA. 


7 

UC. 

3 

GE. 

14 

DG 

2 

VA. 


6 

FC. 

2 

IE. 

13 

OG 

2 





2 

HR 

11 

SG 

2 

FA 


6 

XC. 

2 

FE. 

10 

FG 

1 

UA. 


6 

KC. 

1 

YE. 

9 

GG 

1 






KR 

6 

LG 

1 

AA. 


3 



OE. 

3 

TG 

1 

XA. 


2 



JE. 

2 

YG_ 

1 

JA 


1 

FD 

60 

ZE. 

2 



KA 


1 

ND 

52 

AE. 

1 



ZA 


1 

AD. 

27 

XE. 

1 






RD. 

17 



TH. 

78 

AB 


6 

on 

12 



SH.. 

26 

MB. 


6 

LD. 

9 



GH. 

20 

DB. 


4 

DD..... 

8 

OF.... 

25 

CH 

14 

EB 


4 

ID... 

6 

EF.... 

18 

EH 

7 

OB 


4 

TD.. 

6 

SF__ 

12 

NH 

4 

LB 


3 

SD_ 

5 

FF. 

11 

WH. 

4 

SB. 


3 

YD...... 

4 

YF.... 

11 

OH. 

3 



3 

im 

3 

TF 

10 

PH 

3 

- 



wn 

2 

NF 

9 

RH.. 

3 

TR- 


2 

nn 

1 

OF 

8 

AR. 

2 

NB- 


2 


1 

TF 

7 

DH..... 

2 



2 

Rn 

1 

RF 

6 

LH._ 

1 

RB.. 

YB 


2 

Mn 

1 

HF.. 

5 

MH... 

1 

HB 


1 

pn 

1 

AF. 

4 

XH. 

1 

PB. 


1 

XD...... 

1 

LF... 

3 

YH... 

1 

































































































































































































































126 


AJ. ... 
BJ.... 
DJ.... 
EJ..... 

NJ. „, 

OJ. .„ 

RJ_ 

CK...„ 

AK. .... 
IK..... 

NK. „_ 

OK. .... 
RK-.... 


AL..... 

EL..... 


34 

33 

30 

30 

27 

27 

20 

17 

13 

12 

0 

7 


OL.. 

PL...... 


UL._ 

CL._ 

NL._ 


Table 9-A, Contd .—The 4S8 dijffereni digraphs <j^ Table 6, arra/nged first alphabetically according 
to their final letters, and then according to their absohdejreguendes 

TI_ 

FI_ 

SI. 

HI_ 

NI_ 

RI- 

DI_ 

El_ 

LI- 

AI_ 

WI_ 

VI_ 

MI_ 

Cl_ 

PI- 

GI_ 

01 - 

UI_ 

YI_ 

JBI_ 

;KI_ 

XI_ 

ZI_ 


DL._ 

FL._ 

GL-_ 


32 

29 


YU _ 

HL.- 

_ 

_ 


IM— 

MM... 


19 

18 

6 

6 

5 

6 

5 

6 
3 
2 
2 
2 
2 
1 
1 
1 

25 

14 

14 

13 


TN.... 

YN.... 

DN.... 

SN.... 

GN.... 

HN.... 

WN.... 

CN.... 

KN.... 

LN.... 

PN.... 

fiH.... 


IM._ 

RM._ 

TM._ 

DM._ 

NM._ 


UM... 


PM.... 

SM._. 

HM.... 

LM.... 


YM._ 

BM._ 


CM.... 

FM.... 


CM.... 

QM.... 


EN._ 

ON...... 


5 

5 

5 

4 

3 

2 

2 

2 

1 

1 

1 

1 

1 

111 

77 

76 


TO_ 

CO_ 

10 ._ 

FO._ 

RO_ 

HO_ 

iro_ 

NO_ 

PO_ 

DO_ 

SO_ 


MO_ 

YO_ 

GO_ 

00 _ 

BO_ 

AO_ 

JO._ 


UO... 

VO... 


OP_ 

EP._ 


10 

6 


25 

20 


RR... 

FR... 


GR._ 

SR-_ 

CR._ 

NR._ 

YR_ 


MR.... 

OR... 


WR.... 

XR.... 


Table 9-A, ConcIuddd.-^Y%« 4S8 different digraphs of Table 6, arranged first 

according to their final letters, amd then according to their absolute frequencies 


64 

RP_ 

13 

i ES_ 

54 

OT 

19 


21 

AP_ 

12 

; AS- 

41 




8 

PP.. 

11 

! IS_ 

35 

DT 



7 

SP_ 

10 

RS.. 

31 

YT._ 

16 

VII 

7 

MP_ 

8 

NS_ 

24 

CT 



6 

IP_ 

7 

SS_ 

19 

UT 



4 

DP._ 

5 

TS_ 

19 

FT 



4 

LP. 

3 

OS 

14 

LT 



8 

NP_ 

3 

DS_ 

13 

PT 



3 

YP_ 

3 

US_ 

12 

XT 



2 

GP_ 

2 

YS_ 

11 

GT 



1 

TP_ 

2 

LS . _ 

6 

MT 



1 

UP_ 

2 

PS..... 

6 

BT 



1 

XP. 

2 

HS 

4 

VT 



1 

FP 

1 

MS_ 





1 

HP_ 

1 

FS.. 

3 

OU 

37 

UV 


EQ._..... 

1 

12 

GS_ 

3 

QU- 

15 


50 

DQ._ 

2 

BS_ 

1 

AU._ 

13 

TW...... 

41 

HQ.- 

1 

KS_... 

1 

1 

SU-. 

HU.. 

11 

8 

OW... 

ES?._ 

41 

HQ- 


ws_ 

1 

NU....... 

7 

DW 

40 

28 

TQ.- 


xs. 

1 

DU... 

5 

RW... 

20 

ER... 

87 



RU 

5 

SW 

OR._ 

64 

NT 

82 

TU 

5 

AW 

19 

AR._ 

44 

ST... 

63 

CU 

4 

NW 

18 

UR 

31 

AT.. 

47 

EU 

g 


17 

IR._ 

27 

RT_ 

42 

FU._ 

3 

LW.. 

CW 

16 

PR.. 

18 

RT 

37 

PII 

3 

FW 

15 

HR.. 

17 

HT._ 

28 

BU 

2 

fiW 

13 

TR._ 

17 

IT._ 

27 

GU 

2 


12 

in 

DR.. 

12 







2 

2 

2 

1 

25 

20 

7 

7 

5 

3 

3 

2 

1 

1 

1 


Pff... 

Yff... 


IX.... 

EX. ... 
OX.... 

TY.... 

AY.... 

LY.... 

RY..... 

BY..... 

NY..... 

EY. .... 


MY.. 

OY.. 

CY.... 

DY._ 

FY._ 

HY._ 

PY._ 

SY-_ 


WY... 


EZ.._ 

TZ. 


1 

1 

15 

7 

1 

41 

12 

10 

9 

7 

5 

4 

2 

2 

1 

1 

1 

1 


Total.... 5, 000 


148274—38--9 






















































































































































































































































g .ddddd 













































































































































































































128 



138 


Tabi<b 9-^D, €onciud0di*^l%« 717 digraphe eompOting 76% qf , the BfiOO digraphs ^ Tabh 6} 
arranged alphed>«ticttlly aeeording to their final letters \ 

(2) AND ACCORDING TO THEIR ABSOLUTE FREQUENCIES—Continued 


OP._ 

25 

ES_ 

54 

AT 

47 

QO 


EP.. 

20 

AS_ 

41 

RT 

42 

AU 




IS_ 

35 

ET___ 

37 





RS 

31 

HT 

28 

IV._ 

25 

ER 

87 

RS 

24 

IT __ 

27 

EV._ 

20 

OR 

64 

ss. 

19 

OT 

19 



AR 

44 

re 

19 


19 

TW... 

36 

UR._ 

31 

OS_ 

14 

DT._ 

15 



IR* 

27 

DS 

13 

YT._ 

15 

lA - 

. 15 

PR._ 

18 



CT._... 

14 

TY... 

41 

HR._ 

17 

NT 

82 





TR._ 

17 

ST.. 

63 

OU._ 

37 

Total.... 

.. 3.745 


Tabli! 9—E. —All the 4S& differerd digraphs of Table 6 arranged alphabetically first according to 
their final letters and then according to their initial letters 

(SEE TABLE 6.—READ DOWN THE COLUMNS)' 


Table 10-A .—The 56 trigraphs appearing 100 or more times in the 60,000 letters of Government 
plain-teat telegrams arranged according to their absolvie frequencies 


ENT.. . 

_ 569 

TOP. _ 

. 174 

ETfJ! 


ION. _ 

_ 260 

NTH. _ 

. i7i 



AND. _ 

_ 228 


_ 170 

MEN 


ING. _ 

22R 

TWO 

IRS 

REV 


IVE_ 

_ 225 

ATI _ 

IfiO 



TIO_ 

__ 221 

THR. _ 

_ 168 

lINb 


FOR. _ 

....:__ 218 

NTY. _ 

_ 157 

NET 


OUR. _ 

_ 211 

HRE... 

153 



THL _ 

. 211 

nsN... 

168 

STA 


ONE. _ 

_ 210 

FOU... 

152 

ter _ 

1 1 K 

NIN... 

. 207 

ORT... 

146 

BQU._ 

11^ 

STO,.... 

_ 202 

REE... _ 

_ 146 

RRn 

115K 

EEN. _ 

196 

SIX... 

146 

TED 

. * J- o 

112 

OHT. . . 

196 

ASH... 

_ 143 

RRT 

1 

INB. _ 

_ 192 

DAS... 

_ 140 

HIR_ 

1Q0' 

VEN-.--..... 

_ 190 

IGR.. 

140 

IRT 


EVE_ 

_ 177 

ERE... 

138 

DRR 

ini 

TEST_ 

_ 176 

COM... 

136 


inn 

TEE. _ 

_ 174 

ATE.- 

_ 136 




























































































































































































































180* 


Tabib 10-^. The $6 in^aphe appearing 100 or more times in the SO,OOO Utters of Government 
plain-text telegrams alramged first olphaheUeaUif according to their initial letters and then 
according to their ahsolute frequences 


ANT) 

_ 228 

GHT. 

iflfi 

REE _ 

146 

ATT 

IfiO 




11S 

A?JH 

... 143 

HRE ... _. 

163 



ATE.. 

_ 136 

HIR.___ 

....... 106 







SIX............... 

. 146 

OOM 

1.3fi 

TON 

260 





ING. 

..._ 226 



DAS. 

_ 140 

TVE 

226 




.. 101 ' 

INE... 

192 



DRE 

100' ‘ 

IGH... 

. 140 

TIO_._... 

. 221 

EElH ' 


IRT..:.. 

. 105 


174 

... 569, 
196’ 

men... 

....1... 131 

TOP............ 

... 174 

EVE 

- K. 177 • 
‘176' 



TWE 

_ 170 

KIN._.._ 

:_ 207 ' 

TWO._ 

........i.. 163 

ERE._ 

... 13'0 ' 

A. _ _ _ 

171 

THR.;.._ 

. 158 

EIG._ 

_ 1316 

..NTY,; . V. 

_ 167 

TER. _ 

_ 115 

ERS _ 

_ 126 

NET. _ 

_ 118 

TED... . 

_ 112 

a:w........i..... 

114 

’ ' . V, • 


UND. _ .L.. 


liIRT 

_ 109 

■ ■ '-(joit, _ 

91 T 

. 125 



ONE. ... 

_ 210 



fjOR.... . 

21.8 

qET. . 

1^6 

VEN..—........ 

. 190 

rou. _.... 

_ 152' 





FIY. _ 

_ 135 

PER. . 

_ 115 

WEM.. _....... 

. 153 


Table 10-C .—The 56 trijgraphs appearing 100 or more times in the 50,000 Utters of Oovemmeitt 
plainrtext telegrams 'arranged first alphabetically according to their central Utters and then 
according to their absolute freqwhdjis 


DAS. 140 DEll.... 101 HIR:_____ 106 


REN 


196 

IGH. 

140 


6RQ 

VEN 


.. 190 

THI ___ 

211 

AND 

228 



174 

ING 

226' 

WEN 


153 

OHT 

. 196 

ONE 

210 



146 


168 

INE 

192 

NEW... 


131 



UND 

125 

SEV 


.. 131 

TTO 

_ 221 



NET_ 


.. 118 



ION 

260 

PER-_ 


... 115 

NIN....... 

....._ 207 

FOR.......... 

21R 

TER_ 


... 115 

STY 

_ 146 

TOP 

174 

RED 


... 113 

EIG_ 

136 

FOU_ 

162 

TED.._ 


... 112 

FIV._ 

_ 135 

COM._ 

_ 136 


131 


Table 10-C, Concluded .—The 66 trigrams appearing 100 gr more times in the 60^000 letters <f 
Government plain-text telegrams arranged first alphabetically according to their central Utters 
and then according to their absolute frequencies 


EQU _ 

_ 114 

DRE. . 

_ 100 

STA _ 

... 115 

HRE _...... 

-_ 153 

EST . 

__ 176 

OUR 

_ _ 211 

ORT_ 

- 146 


202 

IVE._ 

_ 225 

ERE 




EVE. 

1 77 

ERS 

_ 126 

ATI 




ERI ... 

_ 109 

NTY. 




IRT.... _ 

- 105 

ATE 

_ 136 



Table 10-D.— The 56 trigraphs appearing 100 or more times in the 60,000 Utters of Government 
plain-text teUgrams arranged first alphabetically according to their firud Utters and then according 
to their absolute frequencies 

STA. __ 

- 115 

IGH 

140 

TFR 

115 





HIR 

. 106 

AND. _ 

- 228 

THI _ 

211 

OER 


UND. _ 

_ 126 

ATT 




RED.__;_ 

. 113 

ERI . 




TED _ 

- 112 




...:.- 140 



ROM 

136 



IVE. . 

. 225 





ONE. __ 

..—.. 210 

ION. _ 

. 260 

ENT. . 

.. 569 

INE. _ 

EVE. _ 

_ 192 

- 177 

NIN........ . 

EEN 

- 207 

. 196 

EST. _ 

. 176 

TEE. _ 

TWE _ 

- 174 

. 170 

VEN..... . 

WEN 

. 190 

163 

NET. 

. 118 

HRE. _ 

REE._ 

. 163 

_ 146 

MEN 

TIO 

. 131 

IRT. _ 

_ 105 

ERE _ 

138 

STf) 

202 

FOU. _ 

_ 152 

ATE 




EQU. _ 

_ 114 

DRE .. 

100 


.. 





TOP 

1 *74 

FIV 

_ 135 

ING. ___..... 

EIG. _ 

- 226 

_ 135 

FOR 

218 

SEV. _ 

- 131 



OIIR 

211 

SIX. _ 

146 

NTR _ 

_ 171 

THR. _ _ 

... 158 




ASH.- 143 PER.- 116 NTY-.. 167 


ii 

il 

























































































































































182 


133 


Tablb 11-A. — Tk* 64 ietragrapht appearing 60 or more times in the 60,000 L 


TTON 

plain-text telegrams arranged 

218 THIR...... 

according to their ahsolvie frequencies 

_ 104 ASHT_ 


EVEN 

168 

EENT 

102 

HUNT) 


TEEN 

1fi.3 

REQU 

98 

nRED 



Ifil 

HTRT 

97 

RTOn 



__ 154 

COMM. 

93 

TVEn 



l.'iS 

QUES..... 

_ 87 

ENTS.. 


NINE._ 

1 S3 

UEST 

37 

FFIC.. 


TWEN 

_ 162 

EQUE. 

8fi 

PROM 


THRE_ 

149 

NDRE 

77 

IRTY 


FOUR...... 

. 144 

OMMA..... 

_ 71 

RTEE 


IGHT 

140 

LLAR..... 

71 

UNDR._ 


FIVE._ 

13S 

OLLA. 

70 

NAUG _ 


HREE._ 

. 134 

VENT 

_ 70 

OURT._ 


KIGH._ 

132 

DOLL..... 

fiS 

UOHT . 


DASR_ 

132 

LARS 

08 

STAT. 


SEVE. 

121 

THIS 

R8 

AIICJH 


EamL.-.. 

tfsi 

PERI. 

67 

CENT 


MENT...... 

. Ill 

ERIO. 

... 66 

FICE_ 



Table 11-B .—The 54 ietragraphs appearing 50 or more times in the 50,000 letters of Oovem- 
ment plain-text telegroms, arranged first alphabetically according to tiuir iniiial letters, and then 
according to their ahaolvte fregv^ncies 


: ASHT_ 

_ 64 

HREE 

134 

AUGH 

S2 

HTRT 

97 



HUND 

04 

i oomL _ 

93 



! GENT_ 

S2 

TGHT 

140 



iVEd 

02 

DASH 

rsa 

IRTY 

SO 

nOT.T. 

08 



I»ED 

. 68 

T.T.AR 

71 



LARS 

08 

EVEN 

_ 168 



ENTY 

. 161 

MENT 

1 11 

EIGH 

132 



ENTH 

. 114 

NINE 

1S3 

EENT_ 

. 102 

NDRE 

77 


. 86 

NAUG 

.so 

1 ERIO 

00 



HOTS. 

02 

OMMA 

. 71 



OT.T.A 

.. 70 

I FOUR.. 

- 144 

OURT,. 

. 66 


FIVE. 136 

FFIC_ 62 

FROM._ 59 

FICE.. 50 


PERI. 67 


THIR.__ 104 

THIS_ 68 

UEST.. 87 

UNDR.. 59 

UGHT_ 66 


Table 11-C .—The 64 tetragraphs appearing 60 or more times in the 50,000 letters of Government 
plain-text telegrams arranged first alphabetically according to their second letters and then 
according to their absolute freguencies 


63 1 

63 ■ 

LARS.. 

NAUG_ 

_ 68 

. 66 

TION 

62 J 

62 1 

NDRE_ 

_ 77 

NINE 

FIVE 

62 * 
69 

TEEN... 

_ 163 

EIGH. 

HTRT * 

59 

, WENT. 

. 153 

RIOD 

59 

! SEVE 

. 121 

FTCE 

69 

MENT. 

111 


56 

EENT 

102 

T.T.AR 

66 

REQU 

98 

DT.T.A 

56 

UEST 

87 


54 ; 

VENT 

70 


52 

PER] 

67 

OMMA.... 

62 

i CENT.. 

. 52 



HREE... 134 

ERIO_ 66 

DRED. 63 

FROM.. 69 

IRTY. 69 


IGHT....... 140 

UGHT_ 56 


THRE.. 149 

THIR.___ 104 


ENTY_ 161 

ENTH.. 114 

ENTS_ 62 

UNDR....-. 59 

FOUR. 144 

COMM....._ 93 

DOLL... 68 


STOP.___ 154 

RTEE.. 59 

STAT... 64 

QUES. 87 

HUND...... 64 

OURT__ 56 

AUGH.,... 52 

EVEN... 168 

IVED... 62 

TWEN._ 152 


Table 11-D .—The 54 tetragraphs appearing 50 or more times in the 50,000 letters of Governmenl 
plain-text telegrams arranged first alphabetically according to their third letters and then according 
to their absolute frequencies 


LLAR.... 71 

STAT.... 54 


EIGH.... 132 

AUGH..... 52 


EVEN.. 168 

TEEN.. 163 

TWEN.. 152 

HREE. 134 

QUES. 87 

DRED.. 63 

IVED.. 62 

RTEE.. 69 


THIR.. 104 

THIS. 68 

ERIO. 66 

FFIC. 62 

OLLA. 70 

DOLL... 68 


COMM.. 98 

OMMA..__ 71 

'WENT. 168 

NINE__ 163 

MENT. Ill 

EENT.. 102 

VENT. 70 

HUND. 64 

CENT. 62 

TION.. 218 

STOP. 154 

RIOD.. 63 

FROM.__ 59 



























































































































































































134 


135 

Table 12, —Average and mean lengths of words 


Table 11-D, Concluded. —The 54 tetragraphs appearing 50 or more times in the 50,000 letters of 
Government plain-text telegrams arranged first alphabetically according to their third Utters and 
then according to their absolute freguencies 


RRQII 

98 

OURT 

66 

TRTY 

.69 



DA.SH 

1.32 

FOUR. . 

. 144 

THRR 

149 

IIRST 

87 

EQUE 

86 

HTRT 

97 



NAUG 

.66 

NDRR 

77 

RNTY 

161 



T.ARS 

68 

RNTH 

* 114 

FIVE._ 

1.86 

PERI. 

. 67 

ENTS_ 

— 62 

SEVE_ 

_ 121 


Table 11-E. —The 54 tetragraphs appearing 50 or more times in the 50,000 Utters of Government 
plain-text telegrams arranged first alphabetically according to their final Utters and then according 
to their absolute freguencies 


OMMA.. 71 DASR.. 132 QUES__ 87 

OLLA._ 70 EIGH._ 132 THIS._ 68 

ENTH._ 114 LARS_ 68 

AUGH._ 52 ENTS_ 62 

FFIC_ 62 

PERI_ 67 

WENT._ 153 

HUND... 64 DOLL... 68 IGHT._ 140 

DRED.. 63 MENT._ 111 

RIOD.. 63 COMM.__ 93 EENT_ 102 

IVED.... 62 FROM.. 59 HIRT._ 97 

UEST._ 87 

TION.. 218 VENT_ 70 

NINE..._ 153 EVEN._ 168 ASHT._ 64 

THRE._ 149 TEEN._ 163 UGHT._ 56 

FIVE._ 135 TWEN.. 152 OURT._ 56 

HREE._ 134 STAT_ 54 

SEVE._ 121 ERIO_ 66 CENT._ 52 

EQUE_ 86 

NDRE._ 77 • STOP._ 154 

RTEE._ 59 REQU._ 98 

FICE._ 50 FOUR._ 144 

THIR._ 104 

LLAR._ 71 ENTY._ 161 

NAUG._ 56 UNDR.. 59 IRTY.. 59 


'Si 

r 


Number of 
letters in 
word 

Number of 
times word 
appears 

Number of 
letters 

1 

378 

378 

2 

973 

1,946 

3 

1,307 

3, 921 

4 

1,635 

6, 540 

5 

1,410 

7, 050 

6 

1, 143 

6, 858 

7 

1,009 

7, 063 

8 

717 

5, 736 

9 

476 

4, 284 

10 

274 

2, 740 

11 

161 

1, 771 

12 

86 

1, 032 

13 

23 

299 

14 

23 

322 

15 

4 

60 

120 

9, 619 

50, 000 


(1) Mean length of aesBagei..-.-.-. 

(2) Average length of messages...—.-..—... 

(3) Mean length of messages----- 

(4) Mode (most frequent) length.. 

(5) It is extremely unusual to find 5 consecutive letters without at least one vowel. 

(6) The average number of letters between vowels is 2. 


6.2 Letters. 

217 Letters. 

191 Letters. 
106-114 Letters. 





















































































Accented lettew_ 

Alphabets: 

Bipi^te- 

Deciphering_ 

Direct standard.. 

Enciphering_ 

Keyword-mixed.. 
Mixed_ 


Beversed standard.. 
Standard_ 


Systematically mixed___ 

Analytic key for cryptanalysis_ 

Arbitrary symbols_ 

Assumptions____ 

Average length of messages_ 

Baconian cipher_ 

Beginnings of messages__ 

Biliteral substitution.... 

Bipartite alphabet_ 

Blanks, number of_ 

Book systems_ 

Censorship, methods for evadmg... 

Characteristic frequency of the letters of a language_ 

Characteristic frequency, suppression of_ 

Checkerboard systems___ 

Checkerboards, A-square_ 

Chinese Official Telegraph Code.. 

Cipher: 

Baconian___ 

Component_:_ 

Distinguished from code.... 

Text, length of, as compared with plain text_ 

Classification of ciphers_ 

Code systems___ 

Distinguished from cipher__ 

Completing the plain component... 

Concealed messages_ 

Condensed table of repetitions_ 

Consonants: 

Distinguished from vowels_ 

Relative frequency of_ 

In succession_ 

Conversion of cipher text_ 

Coordinates on work sheet_ 


( 139 ) 


Fatagtaphs 


Pages 


_ 35c._ 59. 

_ 31c._ 52. 

_ 12a, 16, 19._ 18, 26, 31-33. 

__ 295, 31c_ 49, 52. 

. 31d...53. 

__12o, 16a, 19, 21d, 225, 18, 26,31-33, 

24c, 315. 39, 39, 41, 

62. 

_ 12a, 16, 195, 205_ 18, 26, 33, 36. 

. 12o, 16o, 16,19,205,23, 18,26,26,31- 

38e. 33, 36, 40, 

66. 

_ 31c, e . 62, 63. 

_ 6d, 60 .. 9,103-104. 

__ 135, 48.... 22,100-101. 

__ 465.. .. 9a 

__ 115.. .. 16. 

_ 35e.. .. 6a 

_ 32«.. .. 64 

..... 41... 70-71. 

_ 365, c...69. 

_ 14s... . . .24 

_ 49e.. _ 102 

_ 47c.. ,. 99. 

_ U, 145, 26 .. 12, 23, 41. 

_ 37, 41/.. 63, 71. 

_44,45 .. 73-83,83. 

_ 44.. 73-83. 

_ 48e__ 101. 


.... 36e. 60. 

_ 34^_ 67-5a 

_ 6c, 38c_ 9, 64 

_ 40c._ 69. 

.... 41c._ 70. 

_12a, 13,47,50e,/._ 18,18-22,99, 

104104 

.... 4a, 41p, 475, 48d, s. 7, 71, 99.100, 

101 , 

_ 6c, 38c._ 9, 64 

.... 20a, 34o _ 34 57. 

_47c.. .. 99. 

_.. 27t.. _ 46. 


28, 32c._ 46-47, 63. 

10a, 13, 19.__ 18,18-22,31- 

3a 


32e._ 

21a, e, 34c. 


53. 

88,38,5a 




































































140 



141 


Letters* Paragraphs Pages 


A . 

. 5b-- 

... 8. 


Sic_ 

... 52. 


66, 14e_ 

... 8, 24. 

T f * ^ X 

13d, 31c_ 

... 19,52. 

M ^ 

13d_ 

... 19. 

Messages; 

Beginnings and endings amenable to cryptanalysis- 

_ 32e._ 

_ 49o_ 

... 54. 

... 101. 


. 47c_ 

... 99. 


_ 105_ 

... 15. 

»^ * * 

_ 66, 14e.- 

... 8, 24. 


_ 16o, 226, 24c, 316..„. 

.... 26, 39, 41, 62. 

Mixed alp 

<>Ad __ 

.... 89. 


_ 46d_ 

.... 86. 


16_ 

.... 1. 


.. 12,14 

. 18, 22-25. 


_ 56, 48c 

. 8, 101. 

t't^f n ' 

. 35, 37, 41c... 

. 59-60,63,70. 

Tl^Uiri^^ 1 L j jijj-- -'--I 

36. 

. 61. 

Mu L i 

176, c 

. 27, 28. 

Kuixii« ^ fl 11 u 

_ 9,11, 25_ 

.... 11-13,16-17, 

Deviations from- 

_ 136. 

... 40. 47c. 

36 

41. 

.... 19. 

Nulls-- 

. 61. 


. 33d. 

. 56. 


_ 49o_ 

.... 101. 

JPuiaDCulu^J' 01 UQ-CBStt^CS---— - 

_ 20o_ 

. 34. 

Plain-text unit.... 

41c 

- 70. 

73—83 84-98. 

Playfair cipher...-.. 

_ 

_ 46d.... 

. 86. 

Polyalphabetic cipher distinguished from monoalphabet. 

... 12. 14. 

... 41. 

... 18,22-26. 

. 70-71. 

PolygrajAic^substHi^o^^^^^^^ 

27c 

. 44. 

Prerequisites for cryptographic work. 

Probable-word method- 

2 

_ 33__ 

. 2-5. 

. 55-57. 


_ 41e. 

. 71. 

Punctuation in telegraphic text- 

_ 10c. 

... 35d. 

. 15. 

. 60. 


. 35e. 

. 60. 

^ b of blanks 

. 14/.. 

. 24. 

frequenc^s^^ ^ 

_ 106, c, d, 11,146. 

_ 15,15,15,16- 


_ 13ff, 246, c, 27- 

17, 23. 

__ 21,40,41,43- 

H^potltions-.......— ---——- 


46. 

T 

_ 38c._ 

_ 64. 

In a code message—.——.———— -- - -- 

32c._ 

_ 53. 

Of consonants—- 

.... 27/.... 

_ 46. 

Of digrap^ and trigraphs 

.... 27i. 

..... 46. 

1 1 1 1 lu 

_ 16, 205. 

..... 26, 36. 

Reversed standard alpnaDet^*--——- 

_ 26/.. 

__ 43. 

Reversible digraphs indicated on worksheet———- 

..... 5b, 48e.. 

8,101. 


, 23 _ 

40. 

Security of monoalphabet using standard aipnaDets—.—- 

Sequences: 

23___ 

__40. 

. 

__21d... 

__39. 

Unknown__ 

_23.-.- 

_ 40. 


1482T4—38-10 




























































































































142 


Paragraphs 

tr«y 



_ IBa' 16. 205. 38«_ 

« , . ..1. *1, o'' 

Substitution: 

41 


41ff, 42rt _ 




41,. 


41 r 


_ 41r_ 


_ 41_ 

'irr ■ I * ji 1 J 1 j'liu'li'il'iiifSrkii f}7jt 




_ 135, 48._ 



rp ■ 1 

T-eirt +yjw»n nf 


Transposition distinguished from substitution_ 

_ 12. 







. fl, 17 




_ 37d, 405, 49c, d, f. _ 

Vowels: 


r«rtpihfn4iflnnfl wi'f 



29n 



T ( 1 ■ 7 ■ 


_ 10a, 13, 19._ 


33d _ ._ 




_ 33d_ 

Word skeletons. 306. 32e_ ■ 


22 , 100 - 101 . 


15, 15. 

18, 18-22. 


70-71. 

104. 

11-13,27-28. 


Work sheet, preparation of... 































































































